CWE-770

High likelihood

Allocation of Resources Without Limits or Throttling

Parent: CWE-400 - Uncontrolled Resource Consumption

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

2,071 vulnerabilities with CWE-770
CVE-2026-22803 HIGH
SvelteKit 2.49.0-2.49.4 - Denial of Service via Form Remote Function Memory Exhaustion
CVSS 7.5
CVE-2026-0897 HIGH
Keras 3.0.0-3.13.0 - Denial of Service via HDF5 Weight Loading
CVSS 7.5
CVE-2026-22917 MEDIUM
SICK TDC-X401GL Firmware < 1.5.0 - Denial of Service via Improper Input Handling
CVSS 4.3
CVE-2026-22036 MEDIUM
Undici < 6.23.0 and 7.0.0-7.17.2 - Denial of Service via Decompression Chain Exhaustion
CVSS 5.9
CVE-2026-0543 MEDIUM
Kibana 7.0.0-7.17.29 - Authenticated Denial of Service via Email Connector Address Parameter
CVSS 6.5
CVE-2026-0531 MEDIUM
Kibana 7.10.0-7.17.29 - Authenticated Denial of Service via Bulk Retrieval Request
CVSS 6.5
CVE-2026-0530 MEDIUM
Kibana 7.10.0-7.17.29 - Denial of Service via Fleet Resource Exhaustion
CVSS 6.5
CVE-2026-22773 MEDIUM
vLLM 0.6.4-0.11.9 - Denial of Service via Malformed 1x1 Pixel Image
CVSS 6.5
CVE-2026-22025 LOW
CryptoLib < 1.4.3 - Use-After-Free in KMC Server Error Handling
CVSS 3.7
CVE-2025-71396 LOW
SurrealDB before 2.2.2 Denial of Service via JavaScript Scripting
CVE-2025-36319 MEDIUM
Vulnerabilities found in Watson Data Intelligence
CVSS 4.3
CVE-2025-32423 MEDIUM
AutoGPT < 0.6.32 ExtractTextInformationBlock - Memory Exhaustion Denial of Service
CVE-2025-32394 MEDIUM
AutoGPT < 0.6.32 AITextSummarizerBlock - Memory Exhaustion Denial of Service
CVE-2025-61028 HIGH
openlink virtuoso-opensource 7.2.11 - Denial of Service via time_t_to_dt Component
CVSS 7.5
CVE-2025-7737 HIGH
Hitachi Virtual Storage Platform 10G iSCSI - Denial of Service
CVSS 8.6
CVE-2025-46638 HIGH
Dell Bsafe Ssl-j < 7.4 - Allocation of Resources Without Limits or Throttling
CVSS 7.5
CVE-2025-11482 HIGH
Allocation of Resources Without Limits or Throttling in the OPC-UA Server
CVSS 7.5
CVE-2025-57798 MEDIUM
Joplin has Denial of Service (DoS) via Uncontrolled Resource Allocation through Title Input
CVSS 5.5
CVE-2025-14870 HIGH
Allocation of Resources Without Limits or Throttling in GitLab
CVSS 7.5
CVE-2025-32425 MEDIUM
AutoGPT < 0.6.32 Platform Containers - Docker Log Disk Exhaustion Denial of Service
CVSS 5.5
CVE-2025-69233 MEDIUM
Apache CloudStack: Domain/account resources limits not honored
CVSS 6.5
CVE-2025-14341 HIGH
Input Data Manipulation in DivvyDrive Information Technologies' DivvyDrive
CVSS 8.3
CVE-2025-66369 HIGH
Samsung Exynos MM - Denial of Service via 5G NR NAS Registration Accept Message Handling
CVSS 7.5
CVE-2025-70071 MEDIUM
Assimp 6.0.2 - Denial of Service via FBX Parser Vector Data Array
CVSS 5.9
CVE-2025-70069 HIGH
Assimp 6.0.2 - Denial of Service via FBXConverter.cpp ConvertMeshMultiMaterial Method
CVSS 7.5
Details
Vulnerabilities 2,071
Exploit Likelihood High