CWE-770

High likelihood

Allocation of Resources Without Limits or Throttling

Parent: CWE-400 - Uncontrolled Resource Consumption

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

1,858 vulnerabilities with CWE-770
CVE-2026-8280 MEDIUM
Allocation of Resources Without Limits or Throttling in GitLab
CVSS 6.5
CVE-2026-1659 HIGH
Allocation of Resources Without Limits or Throttling in GitLab
CVSS 7.5
CVE-2026-42561 HIGH
Python-Multipart: Denial of Service via unbounded multipart part headers
CVSS 7.5
CVE-2026-28383 MEDIUM
Grafana plugin resources can lead to unbounded memory allocation
CVSS 6.5
CVE-2026-28376 MEDIUM
Grafana Live push endpoint allows unbounded memory allocation leading to OOM
CVSS 6.5
CVE-2026-8466 HIGH
Unbounded buffer accumulation in multipart header parsing causes denial of service in cowboy
CVE-2026-42583 HIGH
Netty: Lz4FrameDecoder resource exhaustion
CVSS 7.5
CVE-2026-42582 HIGH
Netty: HTTP/3 QPACK literal unbounded allocation
CVSS 7.5
CVE-2026-44579 HIGH
Next.js: Denial of Service via connection exhaustion in applications using Cache Components
CVSS 7.5
CVE-2026-44004 HIGH
vm2: Host Process OOM DoS via Buffer.alloc (Timeout Bypass)
CVSS 7.5
CVE-2026-44577 MEDIUM
Next.js: Denial of Service in the Image Optimization API
CVSS 5.9
CVE-2026-41227 HIGH
BIG-IP HTTP/2 Layer 7 Dos Protection vulnerability
CVSS 7.5
CVE-2026-40629 HIGH
F5 BIG-IP SSL/TLS - Virtual Server Denial of Service
CVSS 7.5
CVE-2026-40423 HIGH
F5 BIG-IP SIP Profile - TMM Denial of Service
CVSS 7.5
CVE-2026-39803 HIGH
HTTP/1 chunked body reader ignores length cap in bandit
CVSS 7.5
CVE-2026-44931 MEDIUM
malcontent: Disk Space Exhaustion via Globally Accessible D-Bus API
CVE-2026-8202 MEDIUM
Post-authentication CPU utilization DoS via $trim/$ltrim/$rtrim operators
CVSS 4.3
CVE-2026-40902 HIGH
PhpSpreadsheet: CPU Denial of Service via Unbounded Row Number in XLSX Row Dimensions
CVSS 7.5
CVE-2026-40863 HIGH
PhpSpreadsheet: CPU Denial of Service via Unbounded Row Index in SpreadsheetML XML Reader
CVSS 7.5
CVE-2026-44240 HIGH
basic-ftp allows a malicious FTP server to cause client-side denial of service via unbounded multiline control response buffering
CVSS 7.5
CVE-2026-44219 LOW
ciguard: SCA HTTP client reads response body without size cap
CVSS 3.7
CVE-2026-42444 LOW
NanaZip: Unbounded resource consumption in NanaZip littlefs parser via attacker-controlled BlockCount
CVSS 3.3
CVE-2026-23826 HIGH
HPE Aruba AOS-8 Network Management Service - Unauthenticated Denial of Service
CVSS 7.5
CVE-2026-41284 HIGH
Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling
CVSS 7.5
CVE-2026-22925 HIGH
Siemens Simatic CN 4100 < V5.0 - Allocation of Resources Without Limits or Throttling
CVSS 7.5
Details
Vulnerabilities 1,858
Exploit Likelihood High