CWE-770
High likelihoodAllocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
1,720 vulnerabilities with CWE-770
CVE-2026-34593
HIGH
Ash Framework: Ash.Type.Module.cast_input/2 atom exhaustion via unchecked Module.concat allows BEAM VM crash
CVSS 7.5
CVE-2026-34829
HIGH
Rack: Denial of Service via Unbounded Multipart File Upload Without Content-Length
CVSS 7.5
CVE-2026-34826
MEDIUM
Rack: Unbounded Range Count in get_byte_ranges Enables DoS
CVSS 5.3
CVE-2026-31935
HIGH
Suricata http2: unbounded resource consumption
CVSS 7.5
CVE-2026-32145
HIGH
Multipart form body parser bypasses body size limits in wisp
CVE-2026-5316
MEDIUM
Nothings stb stb_vorbis.c setup_free allocation of resources
CVSS 4.3
CVE-2026-34517
MEDIUM
AIOHTTP: Late size enforcement for non-file multipart fields causes memory DoS
CVSS 5.3
CVE-2026-34516
HIGH
AIOHTTP: Multipart Header Size Bypass
CVSS 7.5
CVE-2026-34513
HIGH
AIOHTTP: Denial of Service (DoS) via Unbounded DNS Cache in TCPConnector
CVSS 7.5
CVE-2026-22815
HIGH
AIOHTTP: Uncapped memory usage possible through aiohttp allowing unlimited trailer headers
CVSS 7.5
CVE-2026-34165
MEDIUM
go-git: Maliciously crafted idx file can cause asymmetric memory consumption
CVSS 5.0
CVE-2026-21710
HIGH
Node.js 18.* - DoS
CVSS 7.5
CVE-2026-32980
HIGH
OpenClaw < 2026.3.13 - Resource Exhaustion via Unauthenticated Telegram Webhook Request
CVSS 7.5
CVE-2026-33871
HIGH
Netty HTTP/2 CONTINUATION Frame Flood DoS via Zero-Byte Frame Bypass
CVSS 7.5
CVE-2026-26061
HIGH
Fleet's unbounded request body read allows remote Denial of Service
CVSS 7.5
CVE-2026-33743
MEDIUM
Incus vulnerable to denial of source through crafted bucket backup file
CVSS 6.5
CVE-2026-33658
LOW
Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
CVE-2026-33621
MEDIUM
PinchTab: Unapplied Rate Limiting Middleware Allows Unbounded Brute-Force of API Token
CVSS 4.8
CVE-2026-33541
MEDIUM
TSPortal's Uncontrolled User Creation via Validation Side Effects Leads to Potential Denial of Service
CVSS 6.5
CVE-2026-33438
MEDIUM
Stirling-PDF vulnerable to DoS via add-watermark
CVSS 6.5
CVE-2026-4897
MEDIUM
Polkit: polkit: denial of service via unbounded input processing through standard input
CVSS 5.5
CVE-2026-27663
MEDIUM
Siemens Cpci85 Central Processing/communication < V26.10 - Denial of Service
CVSS 6.5
CVE-2026-33219
MEDIUM
NATS is vulnerable to pre-auth DoS through WebSockets client service
CVSS 5.3
CVE-2026-33332
HIGH
NiceGUI's unvalidated chunk size parameter in media routes can cause memory exhaustion
CVSS 7.5
CVE-2026-29772
MEDIUM
Astro: Memory exhaustion DoS due to missing request body size limit in Server Islands
CVSS 5.9
Details
Vulnerabilities
1,720
Exploit Likelihood
High