CWE-770

High likelihood

Allocation of Resources Without Limits or Throttling

Parent: CWE-400 - Uncontrolled Resource Consumption

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

1,720 vulnerabilities with CWE-770
CVE-2026-40036 HIGH
Unfurl < 2026.04 - Denial of Service via Unbounded zlib Decompression
CVSS 7.5
CVE-2026-39414 MEDIUM
MinIO affected a DoS via Unbounded Memory Allocation in S3 Select CSV Parsing
CVSS 6.5
CVE-2026-35401 HIGH
Saleor has a resource exhaustion vulnerability in GraphQL queries
CVSS 7.5
CVE-2026-33756 HIGH
Saleor Affected by Denial of Service via Unbounded GraphQL Query Batching
CVSS 7.5
CVE-2026-32288 MEDIUM
Unbounded allocation for old GNU sparse in archive/tar
CVSS 5.5
CVE-2026-32283 HIGH
Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls
CVSS 7.5
CVE-2026-32280 HIGH
Unexpected work during chain building in crypto/x509
CVSS 7.5
CVE-2026-29181 HIGH
OpenTelemetry-Go multi-value `baggage` header extraction causes excessive allocations (remote dos amplification)
CVSS 7.5
CVE-2026-5762 MEDIUM
ReportIncident DiscussionTools integration causes slow requests
CVE-2026-35526 HIGH
Strawberry GraphQL affected by a Denial of Service via unbounded WebSocket subscriptions
CVSS 7.5
CVE-2026-35480 MEDIUM
go-ipld-prime's DAG-CBOR decoder unbounded memory allocation from CBOR headers
CVSS 6.2
CVE-2026-35457 HIGH
libp2p-rust has unbounded rendezvous DISCOVER cookies enable remote memory exhaustion
CVSS 8.2
CVE-2026-35405 HIGH
libp2p-rendezvous: Unlimited namespace registrations per peer enables OOM DoS on rendezvous servers
CVSS 7.5
CVE-2026-33034 HIGH
Potential denial-of-service vulnerability in ASGI requests via memory upload limit bypass
CVSS 7.5
CVE-2026-20431 MEDIUM
Mediatek, Inc. MediaTek Chipset < MT6813 - Denial of Service
CVSS 6.5
CVE-2026-35441 MEDIUM
Directus Affected by GraphQL Alias Amplification Denial-of-Service Due to Missing Query Cost/Complexity Limits
CVSS 6.5
CVE-2026-34756 MEDIUM
vLLM Affected by Unauthenticated OOM Denial of Service via Unbounded `n` Parameter in OpenAI API Server
CVSS 6.5
CVE-2026-34755 MEDIUM
vLLM Affected by Denial of Service via Unbounded Frame Count in video/jpeg Base64 Processing
CVSS 6.5
CVE-2026-34148 HIGH
Fedify affected by resource exhaustion caused by unbounded redirect following during remote key/document resolution
CVSS 7.5
CVE-2026-34824 HIGH
Mesop: Unbounded Thread Creation in WebSocket Handler Leads to Denial of Service
CVSS 7.5
CVE-2026-34052 MEDIUM
LTI JupyterHub Authenticator: Unbounded Memory Growth via Nonce Storage (Denial of Service)
CVSS 5.9
CVE-2026-35562 HIGH
Allocation of resources without limits in parsing components in Amazon Athena ODBC driver
CVSS 7.5
CVE-2026-25043 MEDIUM
Budibase: Unauthenticated Password Reset Endpoint Lacks Rate Limiting, Enabling Email Flooding
CVSS 5.3
CVE-2026-26477 MEDIUM
Dokuwiki 2025-05-14b - DoS
CVSS 4.3
CVE-2026-34827 HIGH
Rack: Algorithmic-Complexity DoS in Rack::Multipart::Parser
CVSS 7.5
Details
Vulnerabilities 1,720
Exploit Likelihood High