CWE-770
High likelihoodAllocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
1,720 vulnerabilities with CWE-770
CVE-2026-40036
HIGH
Unfurl < 2026.04 - Denial of Service via Unbounded zlib Decompression
CVSS 7.5
CVE-2026-39414
MEDIUM
MinIO affected a DoS via Unbounded Memory Allocation in S3 Select CSV Parsing
CVSS 6.5
CVE-2026-35401
HIGH
Saleor has a resource exhaustion vulnerability in GraphQL queries
CVSS 7.5
CVE-2026-33756
HIGH
Saleor Affected by Denial of Service via Unbounded GraphQL Query Batching
CVSS 7.5
CVE-2026-32288
MEDIUM
Unbounded allocation for old GNU sparse in archive/tar
CVSS 5.5
CVE-2026-32283
HIGH
Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls
CVSS 7.5
CVE-2026-32280
HIGH
Unexpected work during chain building in crypto/x509
CVSS 7.5
CVE-2026-29181
HIGH
OpenTelemetry-Go multi-value `baggage` header extraction causes excessive allocations (remote dos amplification)
CVSS 7.5
CVE-2026-5762
MEDIUM
ReportIncident DiscussionTools integration causes slow requests
CVE-2026-35526
HIGH
Strawberry GraphQL affected by a Denial of Service via unbounded WebSocket subscriptions
CVSS 7.5
CVE-2026-35480
MEDIUM
go-ipld-prime's DAG-CBOR decoder unbounded memory allocation from CBOR headers
CVSS 6.2
CVE-2026-35457
HIGH
libp2p-rust has unbounded rendezvous DISCOVER cookies enable remote memory exhaustion
CVSS 8.2
CVE-2026-35405
HIGH
libp2p-rendezvous: Unlimited namespace registrations per peer enables OOM DoS on rendezvous servers
CVSS 7.5
CVE-2026-33034
HIGH
Potential denial-of-service vulnerability in ASGI requests via memory upload limit bypass
CVSS 7.5
CVE-2026-20431
MEDIUM
Mediatek, Inc. MediaTek Chipset < MT6813 - Denial of Service
CVSS 6.5
CVE-2026-35441
MEDIUM
Directus Affected by GraphQL Alias Amplification Denial-of-Service Due to Missing Query Cost/Complexity Limits
CVSS 6.5
CVE-2026-34756
MEDIUM
vLLM Affected by Unauthenticated OOM Denial of Service via Unbounded `n` Parameter in OpenAI API Server
CVSS 6.5
CVE-2026-34755
MEDIUM
vLLM Affected by Denial of Service via Unbounded Frame Count in video/jpeg Base64 Processing
CVSS 6.5
CVE-2026-34148
HIGH
Fedify affected by resource exhaustion caused by unbounded redirect following during remote key/document resolution
CVSS 7.5
CVE-2026-34824
HIGH
Mesop: Unbounded Thread Creation in WebSocket Handler Leads to Denial of Service
CVSS 7.5
CVE-2026-34052
MEDIUM
LTI JupyterHub Authenticator: Unbounded Memory Growth via Nonce Storage (Denial of Service)
CVSS 5.9
CVE-2026-35562
HIGH
Allocation of resources without limits in parsing components in Amazon Athena ODBC driver
CVSS 7.5
CVE-2026-25043
MEDIUM
Budibase: Unauthenticated Password Reset Endpoint Lacks Rate Limiting, Enabling Email Flooding
CVSS 5.3
CVE-2026-26477
MEDIUM
Dokuwiki 2025-05-14b - DoS
CVSS 4.3
CVE-2026-34827
HIGH
Rack: Algorithmic-Complexity DoS in Rack::Multipart::Parser
CVSS 7.5
Details
Vulnerabilities
1,720
Exploit Likelihood
High