CWE-770

High likelihood

Allocation of Resources Without Limits or Throttling

Parent: CWE-400 - Uncontrolled Resource Consumption

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

1,858 vulnerabilities with CWE-770
CVE-2026-42786 HIGH
WebSocket fragmented message reassembly unbounded in bandit
CVE-2026-39804 HIGH
WebSocket permessage-deflate inflate has no output-size cap in bandit
CVE-2026-43507 MEDIUM
Prosody < 0.12.6 and 1.0.0-13.0.0 < 13.0.5 - Unauthenticated Denial of Service via XML Parsing Resource Amplification
CVSS 5.3
CVE-2026-42198 HIGH
pgjdbc 42.2.0 to before 42.7.11 - SCRAM Authentication Denial of Service
CVSS 7.5
CVE-2026-42420 MEDIUM
OpenClaw < 2026.4.8 - Improper Base64 Decoding Size Validation
CVSS 4.3
CVE-2026-41408 MEDIUM
OpenClaw < 2026.3.31 - Disk Exhaustion via Media Download Bypass
CVSS 4.3
CVE-2026-41400 MEDIUM
OpenClaw < 2026.3.31 - Resource Consumption via Oversized WebSocket Frames in voice-call
CVSS 5.3
CVE-2026-41399 HIGH
OpenClaw < 2026.3.28 - Denial of Service via Unbounded Pre-auth WebSocket Upgrades
CVSS 7.5
CVE-2026-32688 HIGH
Atom table exhaustion via HTTP/2 :scheme pseudo-header in plug_cowboy
CVSS 7.5
CVE-2026-42036 MEDIUM
Axios: HTTP adapter streamed responses bypass maxContentLength
CVSS 5.3
CVE-2026-42034 MEDIUM
Axios: HTTP adapter streamed uploads bypass maxBodyLength when maxRedirects: 0
CVSS 5.3
CVE-2026-41324 HIGH
basic-ftp vulnerable to denial of service via unbounded memory consumption in Client.list()
CVSS 7.5
CVE-2026-41309 HIGH
Open Source Social Network (OSSN) Vulnerable to Resource Exhaustion via Malicious Image Processing
CVSS 8.2
CVE-2026-41173 MEDIUM
Unbounded HTTP response body read in OpenTelemetry.Sampler.AWS
CVSS 5.9
CVE-2026-41078 MEDIUM
OpenTelemetry dotnet: Potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
CVSS 5.9
CVE-2026-34062 MEDIUM
Nimiq has Allocation of Resources Without Limits or Throttling in its libp2p request/response
CVSS 5.3
CVE-2026-1660 MEDIUM
Allocation of Resources Without Limits or Throttling in GitLab
CVSS 6.5
CVE-2026-33595 MEDIUM
DoQ/DoH3 excessive memory allocation
CVSS 5.3
CVE-2026-33594 MEDIUM
Outgoing DoH excessive memory allocation
CVSS 5.3
CVE-2026-33254 MEDIUM
Resource exhaustion via DoQ/DoH3 connections
CVSS 5.3
CVE-2026-33260 MEDIUM
Insufficient input validation of internal webserver
CVSS 5.3
CVE-2026-33258 MEDIUM
Crafted zones can cause increased resource usage
CVSS 5.3
CVE-2026-33257 MEDIUM
Insufficient input validation of internal webserver
CVSS 5.3
CVE-2026-33256 MEDIUM
Unbounded memory allocation by internal web server
CVSS 5.3
CVE-2026-22018 LOW
Oracle Java SE & GraalVM DoS via Libraries (8u481, 11.0.30, 17.0.18, 21.0.10, 25.0.2, 26)
CVSS 3.7
Details
Vulnerabilities 1,858
Exploit Likelihood High