CWE-770

High likelihood

Allocation of Resources Without Limits or Throttling

Parent: CWE-400 - Uncontrolled Resource Consumption

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

2,071 vulnerabilities with CWE-770
CVE-2026-58488 MEDIUM
HedgeDoc: Rate-limit bypass via CF-Connecting-IP header spoofing
CVE-2026-61465 LOW
ImageMagick before 7.1.2-26 Memory Allocation Policy Bypass
CVSS 3.3
CVE-2026-57220 HIGH
RabbitMQ Stream Listener < 4.2.6 - Unauthenticated Memory Exhaustion
CVSS 7.5
CVE-2026-57212 HIGH
RabbitMQ management HTTP API accepts request bodies larger than configured max_http_body_size
CVSS 7.7
CVE-2026-59161 HIGH
Excelize: Streaming GetRows row-bound bypass causes attacker-controlled allocation
CVSS 7.5
CVE-2026-54063 HIGH
Excelize: Unbounded Row Index Allocation in Worksheet Parser (checkSheet OOM/Panic DoS)
CVSS 7.5
CVE-2026-53653 HIGH
Grav: Unauthenticated denial of service via unbounded image derivative dimensions
CVE-2026-58661 MEDIUM
n8n - Disk Space Exhaustion via Data-Table File Upload Endpoint
CVSS 4.3
CVE-2026-56309 MEDIUM
Capgo - Plan Bypass via Unrestricted Attachment Upload Endpoint
CVSS 5.4
CVE-2026-56814 MEDIUM
Plug: multipart :length limit is not charged for part headers, enabling unbounded temp-file creation (denial of service)
CVE-2026-40006 HIGH
Apache IoTDB: Unauthenticated heap-exhaustion DoS via unbounded allocation in IoTDB AirGap pipe receiver
CVSS 7.5
CVE-2026-60108 HIGH
Zeek < 8.0.9 Uncontrolled Memory Consumption DoS via FTP Analyzer
CVSS 7.5
CVE-2026-12590 LOW
body-parser vulnerable to denial of service when invalid limit value silently disables size enforcement
CVSS 3.7
CVE-2026-31984 HIGH
DoS through oversized audit log entries in Guardian/CMC before 26.2.0
CVSS 7.5
CVE-2026-49866 HIGH
libp2p: CPU DoS via oversized IHAVE and IWANT control message arrays
CVSS 7.5
CVE-2026-55575 HIGH
LiquidJS: `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforce
CVE-2026-14362 MEDIUM
Denial of service via crafted push/pull gossip message in memberlist
CVSS 4.9
CVE-2026-59873 HIGH
node-tar: Decompression/parse DoS via unlimited input
CVSS 7.5
CVE-2026-59870 MEDIUM
js-yaml quadratic-complexity denial of service via YAML11_SCHEMA !!omap parsing
CVSS 5.3
CVE-2026-59868 MEDIUM
js-yaml: YAML merge-key chains can force quadratic CPU consumption
CVSS 5.3
CVE-2026-49146 HIGH
App::Ack < 3.10.0 - Project .ackrc Memory Exhaustion
CVSS 7.5
CVE-2026-60001 MEDIUM
Openbsd OpenSSH < 10.4 - Allocation of Resources Without Limits or Throttling
CVSS 6.5
CVE-2026-60000 LOW
Openbsd OpenSSH < 10.4 - Allocation of Resources Without Limits or Throttling
CVSS 3.7
CVE-2026-55078 MEDIUM
Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service
CVSS 6.5
CVE-2026-55434 MEDIUM
Coder vulnerable to denial of service via unbounded request body in AI Bridge provider endpoints
CVSS 6.5
Details
Vulnerabilities 2,071
Exploit Likelihood High