CWE-770

High likelihood

Allocation of Resources Without Limits or Throttling

Parent: CWE-400 - Uncontrolled Resource Consumption

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

1,720 vulnerabilities with CWE-770
CVE-2026-34593 HIGH
Ash Framework: Ash.Type.Module.cast_input/2 atom exhaustion via unchecked Module.concat allows BEAM VM crash
CVSS 7.5
CVE-2026-34829 HIGH
Rack: Denial of Service via Unbounded Multipart File Upload Without Content-Length
CVSS 7.5
CVE-2026-34826 MEDIUM
Rack: Unbounded Range Count in get_byte_ranges Enables DoS
CVSS 5.3
CVE-2026-31935 HIGH
Suricata http2: unbounded resource consumption
CVSS 7.5
CVE-2026-32145 HIGH
Multipart form body parser bypasses body size limits in wisp
CVE-2026-5316 MEDIUM
Nothings stb stb_vorbis.c setup_free allocation of resources
CVSS 4.3
CVE-2026-34517 MEDIUM
AIOHTTP: Late size enforcement for non-file multipart fields causes memory DoS
CVSS 5.3
CVE-2026-34516 HIGH
AIOHTTP: Multipart Header Size Bypass
CVSS 7.5
CVE-2026-34513 HIGH
AIOHTTP: Denial of Service (DoS) via Unbounded DNS Cache in TCPConnector
CVSS 7.5
CVE-2026-22815 HIGH
AIOHTTP: Uncapped memory usage possible through aiohttp allowing unlimited trailer headers
CVSS 7.5
CVE-2026-34165 MEDIUM
go-git: Maliciously crafted idx file can cause asymmetric memory consumption
CVSS 5.0
CVE-2026-21710 HIGH
Node.js 18.* - DoS
CVSS 7.5
CVE-2026-32980 HIGH
OpenClaw < 2026.3.13 - Resource Exhaustion via Unauthenticated Telegram Webhook Request
CVSS 7.5
CVE-2026-33871 HIGH
Netty HTTP/2 CONTINUATION Frame Flood DoS via Zero-Byte Frame Bypass
CVSS 7.5
CVE-2026-26061 HIGH
Fleet's unbounded request body read allows remote Denial of Service
CVSS 7.5
CVE-2026-33743 MEDIUM
Incus vulnerable to denial of source through crafted bucket backup file
CVSS 6.5
CVE-2026-33658 LOW
Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
CVE-2026-33621 MEDIUM
PinchTab: Unapplied Rate Limiting Middleware Allows Unbounded Brute-Force of API Token
CVSS 4.8
CVE-2026-33541 MEDIUM
TSPortal's Uncontrolled User Creation via Validation Side Effects Leads to Potential Denial of Service
CVSS 6.5
CVE-2026-33438 MEDIUM
Stirling-PDF vulnerable to DoS via add-watermark
CVSS 6.5
CVE-2026-4897 MEDIUM
Polkit: polkit: denial of service via unbounded input processing through standard input
CVSS 5.5
CVE-2026-27663 MEDIUM
Siemens Cpci85 Central Processing/communication < V26.10 - Denial of Service
CVSS 6.5
CVE-2026-33219 MEDIUM
NATS is vulnerable to pre-auth DoS through WebSockets client service
CVSS 5.3
CVE-2026-33332 HIGH
NiceGUI's unvalidated chunk size parameter in media routes can cause memory exhaustion
CVSS 7.5
CVE-2026-29772 MEDIUM
Astro: Memory exhaustion DoS due to missing request body size limit in Server Islands
CVSS 5.9
Details
Vulnerabilities 1,720
Exploit Likelihood High