CWE-770

High likelihood

Allocation of Resources Without Limits or Throttling

Parent: CWE-400 - Uncontrolled Resource Consumption

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

2,071 vulnerabilities with CWE-770
CVE-2026-15588 MEDIUM
Gdbusserver: glib2: gdbusserver pre-authentication dos via unbounded sasl line buffering
CVSS 5.3
CVE-2026-54490 MEDIUM
websocket-driver: Resource limit bypass via message compression
CVE-2026-50274 HIGH
Datadog dd-trace-go < 2.8.1 - Baggage Header Denial of Service
CVSS 7.5
CVE-2026-50272 HIGH
Datadog dd-trace-js < 5.100.0 - Baggage Header Denial of Service
CVSS 7.5
CVE-2026-50271 HIGH
Datadog dd-trace-py < 4.8.2 - Baggage Header Denial of Service
CVSS 7.5
CVE-2026-44891 HIGH
Netty: Denial of Service via Unbounded Headers in StompSubframeDecoder
CVSS 7.5
CVE-2026-55254 MEDIUM
NCalc: Denial of Service via Unbounded and Non-Terminating Factorial Evaluation
CVSS 4.8
CVE-2026-54465 MEDIUM
websocket-driver: Memory exhaustion in HTTP header parser
CVE-2026-54464 MEDIUM
websocket-driver: Resource limit bypass via message compression
CVE-2026-54463 MEDIUM
websocket-driver: Memory exhaustion via abuse of protocol length headers
CVE-2026-48504 MEDIUM
OpenTelemetry Rust: Unbounded memory allocation in W3C Baggage propagation
CVSS 5.3
CVE-2026-49835 MEDIUM
Sigstore Timestamp Authority: OOM due to unbounded metric label cardinality
CVSS 5.9
CVE-2026-48045 MEDIUM
Zeroconf: Unbounded TC-deferred queue allows LAN-local memory exhaustion via spoofed-source flood
CVSS 6.5
CVE-2026-47184 MEDIUM
Zeroconf: Unbounded DNS record cache allows LAN-local memory exhaustion via multicast flood
CVSS 6.5
CVE-2026-50273 HIGH
Datadog .NET Tracer < 3.43.0 - Baggage Header Denial of Service
CVSS 7.5
CVE-2026-49209 MEDIUM
Symfony UX: Denial of service in symfony/ux-live-component via unbounded batch action requests
CVSS 6.5
CVE-2026-15007 MEDIUM
GitHub Enterprise Server < 3.22 - Authenticated YAML Denial of Service
CVE-2026-62210 MEDIUM
OpenClaw < 2026.6.1 Denial of Service via Remote Media URLs
CVSS 6.5
CVE-2026-54340 HIGH
h2o has HTTP/2 state amplification
CVSS 7.5
CVE-2026-44453 HIGH
h2o is vulnerable to musl libc stack overflow
CVSS 7.5
CVE-2026-44433 MEDIUM
Quicly is vulnerable to memory exhaustion
CVSS 5.3
CVE-2026-55407 MEDIUM
Buffa: Memory Exhaustion Denial of Service in decode_unknown_field via Unbounded Allocation
CVE-2026-21729 HIGH
Loki detected_fields query limits results in unbounded memory allocation
CVSS 7.5
CVE-2026-23538 HIGH
Feast: resource exhaustion via websocket endpoint
CVSS 7.5
CVE-2026-59762 HIGH
F5 Big-ip < 21.1.0.1 - Denial of Service
CVSS 7.5
Details
Vulnerabilities 2,071
Exploit Likelihood High