CWE-770

High likelihood

Allocation of Resources Without Limits or Throttling

Parent: CWE-400 - Uncontrolled Resource Consumption

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

2,071 vulnerabilities with CWE-770
CVE-2026-56811 HIGH
Phoenix transports do not limit channel joins per connection, enabling process-exhaustion denial of service
CVSS 7.5
CVE-2026-42145 LOW
Coolify: File Upload Without Type or Size Validation in Database Backup Restore
CVSS 3.1
CVE-2026-41899 MEDIUM
Coolify unauthenticated feedback endpoint allows Discord webhook abuse
CVSS 6.5
CVE-2026-55646 MEDIUM
vLLM speech-to-text endpoints allocate full upload before enforcing the audio file-size limit
CVSS 6.5
CVE-2026-42546 LOW
OP-TEE has missing OPTEE_MSG_ATTR_TYPE_MASK in cleanup_shm_refs() leaks mobj references
CVSS 3.8
CVE-2026-13698 HIGH
OpenVPN - Missing Release of Memory after Effective Lifetime
CVSS 7.5
CVE-2026-56810 HIGH
mint buffers an entire chunked response chunk in memory in Mint.HTTP1.decode_body/5
CVE-2026-11586 HIGH
curl - WS Auto-PONG Memory Exhaustion
CVSS 7.5
CVE-2026-58465 HIGH
Eclipse Wakaama CoAP Block1 Handler Unbounded Memory Allocation DoS
CVSS 7.5
CVE-2026-11946 HIGH
GetEndpoints Memory Exhaustion in open62541
CVSS 7.5
CVE-2026-9563 HIGH
Eclipse Parsson < 1.1.7 - Uncontrolled Resource Consumption
CVSS 7.5
CVE-2026-33592 HIGH
FindServers Memory Exhaustion in open62541
CVSS 7.5
CVE-2026-54428 HIGH
Apache HttpComponents Core: HPackDecoder Unlimited Header List Size Before SETTINGS ACK
CVSS 7.5
CVE-2026-56150 MEDIUM
Allocation of Resources Without Limits or Throttling in Fleet Server Leading to Denial of Service
CVSS 6.5
CVE-2026-56149 MEDIUM
Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of Service
CVSS 4.9
CVE-2026-49087 MEDIUM
Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service
CVSS 6.5
CVE-2026-20216 HIGH
Cisco Secure Endpoint - ClamAV InstallShield File Format Processing Resource Exhaustion Vulnerability
CVSS 7.5
CVE-2026-14330 MEDIUM
Pipewire: pulse server alloca stack overflow
CVSS 5.5
CVE-2026-57080 HIGH
Net::BitTorrent <= 2.0.1 - Peer-Wire Message Length Memory Exhaustion
CVSS 7.5
CVE-2026-12818 CRITICAL
DVP-12SE Exposure of Sensitive Information Vulnerability
CVE-2026-53426 HIGH
Atom-table exhaustion denial-of-service via JSON parse_document in MDEx
CVE-2026-48933 HIGH
Node - Integer Overflow or Wraparound
CVSS 7.5
CVE-2026-13322 LOW
Kubevirt: virt-handler-rhel9: kubevirt: unbounded virtio-serial readline in virt-handler causes oom denial of service
CVSS 3.8
CVE-2026-54448 MEDIUM
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser
CVSS 6.5
CVE-2026-54037 MEDIUM
LibreChat < 0.8.4-rc1 - Conversation Duplication Rate Limit Bypass
CVSS 6.5
Details
Vulnerabilities 2,071
Exploit Likelihood High