CWE-770
High likelihoodAllocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
2,071 vulnerabilities with CWE-770
CVE-2026-15588
MEDIUM
Gdbusserver: glib2: gdbusserver pre-authentication dos via unbounded sasl line buffering
CVSS 5.3
CVE-2026-54490
MEDIUM
websocket-driver: Resource limit bypass via message compression
CVE-2026-50274
HIGH
Datadog dd-trace-go < 2.8.1 - Baggage Header Denial of Service
CVSS 7.5
CVE-2026-50272
HIGH
Datadog dd-trace-js < 5.100.0 - Baggage Header Denial of Service
CVSS 7.5
CVE-2026-50271
HIGH
Datadog dd-trace-py < 4.8.2 - Baggage Header Denial of Service
CVSS 7.5
CVE-2026-44891
HIGH
Netty: Denial of Service via Unbounded Headers in StompSubframeDecoder
CVSS 7.5
CVE-2026-55254
MEDIUM
NCalc: Denial of Service via Unbounded and Non-Terminating Factorial Evaluation
CVSS 4.8
CVE-2026-54465
MEDIUM
websocket-driver: Memory exhaustion in HTTP header parser
CVE-2026-54464
MEDIUM
websocket-driver: Resource limit bypass via message compression
CVE-2026-54463
MEDIUM
websocket-driver: Memory exhaustion via abuse of protocol length headers
CVE-2026-48504
MEDIUM
OpenTelemetry Rust: Unbounded memory allocation in W3C Baggage propagation
CVSS 5.3
CVE-2026-49835
MEDIUM
Sigstore Timestamp Authority: OOM due to unbounded metric label cardinality
CVSS 5.9
CVE-2026-48045
MEDIUM
Zeroconf: Unbounded TC-deferred queue allows LAN-local memory exhaustion via spoofed-source flood
CVSS 6.5
CVE-2026-47184
MEDIUM
Zeroconf: Unbounded DNS record cache allows LAN-local memory exhaustion via multicast flood
CVSS 6.5
CVE-2026-50273
HIGH
Datadog .NET Tracer < 3.43.0 - Baggage Header Denial of Service
CVSS 7.5
CVE-2026-49209
MEDIUM
Symfony UX: Denial of service in symfony/ux-live-component via unbounded batch action requests
CVSS 6.5
CVE-2026-15007
MEDIUM
GitHub Enterprise Server < 3.22 - Authenticated YAML Denial of Service
CVE-2026-62210
MEDIUM
OpenClaw < 2026.6.1 Denial of Service via Remote Media URLs
CVSS 6.5
CVE-2026-54340
HIGH
h2o has HTTP/2 state amplification
CVSS 7.5
CVE-2026-44453
HIGH
h2o is vulnerable to musl libc stack overflow
CVSS 7.5
CVE-2026-44433
MEDIUM
Quicly is vulnerable to memory exhaustion
CVSS 5.3
CVE-2026-55407
MEDIUM
Buffa: Memory Exhaustion Denial of Service in decode_unknown_field via Unbounded Allocation
CVE-2026-21729
HIGH
Loki detected_fields query limits results in unbounded memory allocation
CVSS 7.5
CVE-2026-23538
HIGH
Feast: resource exhaustion via websocket endpoint
CVSS 7.5
CVE-2026-59762
HIGH
F5 Big-ip < 21.1.0.1 - Denial of Service
CVSS 7.5
Details
Vulnerabilities
2,071
Exploit Likelihood
High