CWE-770
High likelihoodAllocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
1,858 vulnerabilities with CWE-770
CVE-2026-8280
MEDIUM
Allocation of Resources Without Limits or Throttling in GitLab
CVSS 6.5
CVE-2026-1659
HIGH
Allocation of Resources Without Limits or Throttling in GitLab
CVSS 7.5
CVE-2026-42561
HIGH
Python-Multipart: Denial of Service via unbounded multipart part headers
CVSS 7.5
CVE-2026-28383
MEDIUM
Grafana plugin resources can lead to unbounded memory allocation
CVSS 6.5
CVE-2026-28376
MEDIUM
Grafana Live push endpoint allows unbounded memory allocation leading to OOM
CVSS 6.5
CVE-2026-8466
HIGH
Unbounded buffer accumulation in multipart header parsing causes denial of service in cowboy
CVE-2026-42583
HIGH
Netty: Lz4FrameDecoder resource exhaustion
CVSS 7.5
CVE-2026-42582
HIGH
Netty: HTTP/3 QPACK literal unbounded allocation
CVSS 7.5
CVE-2026-44579
HIGH
Next.js: Denial of Service via connection exhaustion in applications using Cache Components
CVSS 7.5
CVE-2026-44004
HIGH
vm2: Host Process OOM DoS via Buffer.alloc (Timeout Bypass)
CVSS 7.5
CVE-2026-44577
MEDIUM
Next.js: Denial of Service in the Image Optimization API
CVSS 5.9
CVE-2026-41227
HIGH
BIG-IP HTTP/2 Layer 7 Dos Protection vulnerability
CVSS 7.5
CVE-2026-40629
HIGH
F5 BIG-IP SSL/TLS - Virtual Server Denial of Service
CVSS 7.5
CVE-2026-40423
HIGH
F5 BIG-IP SIP Profile - TMM Denial of Service
CVSS 7.5
CVE-2026-39803
HIGH
HTTP/1 chunked body reader ignores length cap in bandit
CVSS 7.5
CVE-2026-44931
MEDIUM
malcontent: Disk Space Exhaustion via Globally Accessible D-Bus API
CVE-2026-8202
MEDIUM
Post-authentication CPU utilization DoS via $trim/$ltrim/$rtrim operators
CVSS 4.3
CVE-2026-40902
HIGH
PhpSpreadsheet: CPU Denial of Service via Unbounded Row Number in XLSX Row Dimensions
CVSS 7.5
CVE-2026-40863
HIGH
PhpSpreadsheet: CPU Denial of Service via Unbounded Row Index in SpreadsheetML XML Reader
CVSS 7.5
CVE-2026-44240
HIGH
basic-ftp allows a malicious FTP server to cause client-side denial of service via unbounded multiline control response buffering
CVSS 7.5
CVE-2026-44219
LOW
ciguard: SCA HTTP client reads response body without size cap
CVSS 3.7
CVE-2026-42444
LOW
NanaZip: Unbounded resource consumption in NanaZip littlefs parser via attacker-controlled BlockCount
CVSS 3.3
CVE-2026-23826
HIGH
HPE Aruba AOS-8 Network Management Service - Unauthenticated Denial of Service
CVSS 7.5
CVE-2026-41284
HIGH
Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling
CVSS 7.5
CVE-2026-22925
HIGH
Siemens Simatic CN 4100 < V5.0 - Allocation of Resources Without Limits or Throttling
CVSS 7.5
Details
Vulnerabilities
1,858
Exploit Likelihood
High