CWE-770

High likelihood

Allocation of Resources Without Limits or Throttling

Parent: CWE-400 - Uncontrolled Resource Consumption

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

2,071 vulnerabilities with CWE-770
CVE-2026-13585 HIGH
Asus System Control Interface v3 - Sensitive Information in Resource Not Removed Before Reuse
CVE-2026-46629 MEDIUM
Twig: Unbounded formatter memoisation in twig/intl-extra keyed on template-controlled arguments
CVSS 6.5
CVE-2026-49476 HIGH
Soup Sieve: Memory Exhaustion via Large Comma-Separated Selector Lists in soupsieve
CVSS 7.5
CVE-2026-24271 MEDIUM
Nvidia TensorRT-LLM < v1.3.0 rc14 - Allocation of Resources Without Limits or Throttling
CVSS 6.2
CVE-2026-50651 HIGH
Microsoft .NET and Visual Studio - Network Denial of Service
CVSS 7.5
CVE-2026-50648 HIGH
Microsoft .NET Framework, .NET, and Visual Studio - Network Denial of Service
CVSS 7.5
CVE-2026-50525 HIGH
Microsoft .NET and Visual Studio - Network Denial of Service
CVSS 7.5
CVE-2026-15711 HIGH
Libsoup: soupwebsocketconnection: libsoup: websocket remote denial of service via oversized control frame protocol violation
CVSS 7.5
CVE-2026-47302 HIGH
Microsoft .NET Framework, .NET, and Visual Studio - Network Denial of Service
CVSS 7.5
CVE-2026-59886 HIGH
pyasn1: Uncontrolled resource consumption when converting decoded REAL values
CVSS 7.5
CVE-2026-59200 HIGH
Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()
CVSS 7.5
CVE-2026-56170 HIGH
Microsoft ASP.NET Core - Resource Allocation Denial of Service
CVSS 7.5
CVE-2026-50506 HIGH
Microsoft ASP.NET Core OData - Resource Allocation Denial of Service
CVSS 7.5
CVE-2026-49788 HIGH
Microsoft Windows HTTP/2 - Resource Allocation Denial of Service
CVSS 7.5
CVE-2026-49787 HIGH
Microsoft Windows HTTP.sys - Resource Allocation Denial of Service
CVSS 7.5
CVE-2026-45646 HIGH
Microsoft ASP.NET Core OData - Resource Allocation Denial of Service
CVSS 7.5
CVE-2026-62641 MEDIUM
Roundcube Webmail - Allocation of Resources Without Limits or Throttling
CVSS 4.3
CVE-2026-60081 HIGH
DBI::ProfileData versions before 1.651 for Perl do not limit the path index
CVSS 7.5
CVE-2026-59204 HIGH
Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service
CVSS 7.5
CVE-2026-12707 HIGH
Unbounded path event queue growth in quiche via peer-driven source connection ID rotation
CVSS 7.5
CVE-2026-9140 HIGH
1718-AENTR/1719-AENTR - Denial of Service
CVE-2026-10573 HIGH
1734 POINT I/OTM - Denial of Service via Malformed Inputs on CIP Object
CVE-2026-54429 HIGH
Siemens Simatic S7-PLCSIM Advanced - Allocation of Resources Without Limits or Throttling
CVSS 7.4
CVE-2026-59246 MEDIUM
Zero-length HTTP/2 CONTINUATION frames bypass Mint's header-block byte-size cap and exhaust client memory
CVE-2026-58229 HIGH
Unbounded HTTP/1 response-header and chunked-trailer accumulation in Mint causes memory-exhaustion DoS
Details
Vulnerabilities 2,071
Exploit Likelihood High