CWE-770

High likelihood

Allocation of Resources Without Limits or Throttling

Parent: CWE-400 - Uncontrolled Resource Consumption

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

2,071 vulnerabilities with CWE-770
CVE-2026-54024 MEDIUM
LibreChat: Incomplete Fix for CVE-2024-11171 — Conversation Import Multer Instance Missing File Size Limits
CVSS 6.5
CVE-2026-40211 MEDIUM
PowerDNS DNSdist - Denial of Service via Crafted DoH3 Queries
CVSS 5.3
CVE-2026-12760 MEDIUM
Denial-of-Service Vulnerability via Malformed IPv4 Fragmentation Handling in TP-Link Tapo C200
CVSS 6.5
CVE-2026-49851 HIGH
Mistune: Potential DoS via quadratic-time parsing in parse_link_text
CVSS 7.5
CVE-2026-54297 HIGH
Faraday NestedParamsEncoder < 1.10.6/2.14.3 - Stack Exhaustion DoS
CVSS 7.5
CVE-2026-11972 HIGH
Python Software Foundation CPython - Tarfile Opened in Streaming Mode Mishandles EOF
CVE-2026-46553 LOW
NocoDB: Attachment Size Limit Bypass via Upload-by-URL
CVE-2026-46551 MEDIUM
NocoDB: Missing File Size Enforcement in Upload-by-URL Allows Denial of Service via Disk Exhaustion
CVSS 6.5
CVE-2026-56324 HIGH
Capgo - Rate Limit Bypass via User-Controlled device_id Parameter
CVSS 8.2
CVE-2026-56255 MEDIUM
Capgo - Denial of Service via Unlimited Demo App Creation
CVSS 4.3
CVE-2026-48515 HIGH
MessagePack-CSharp: Multi-dimensional array formatters allocate from unchecked dimensions
CVSS 7.5
CVE-2026-48514 HIGH
MessagePack-CSharp: Unity unsafe blit formatter allocates from unbounded byte length
CVSS 7.5
CVE-2026-48510 HIGH
MessagePack-CSharp: LZ4 decompression allocates from unbounded declared output lengths
CVSS 7.5
CVE-2026-39904 MEDIUM
Gophish 0.12.1 Denial of Service via Office Document Upload
CVSS 6.5
CVE-2026-54285 MEDIUM
opentelemetry-js: Unbounded memory allocation in W3C Baggage propagation
CVSS 5.3
CVE-2026-54283 HIGH
Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS
CVSS 7.5
CVE-2026-54277 HIGH
AIOHTTP: C HTTP Parser Bypasses max_line_size for Fragmented Lines
CVSS 7.5
CVE-2026-54274 HIGH
AIOHTTP: Incomplete websocket frame payloads bypass memory limits
CVSS 7.5
CVE-2026-54273 HIGH
AIOHTTP: HTTP/1 Pipelined Requests Queue Without Limit
CVSS 7.5
CVE-2026-54270 MEDIUM
protobufjs: Memory amplification from preserved unknown fields in binary decode
CVSS 5.3
CVE-2026-42127 HIGH
Grafana pre-auth DoS through arbitrarily large input to public dashboard query handler
CVSS 7.5
CVE-2026-49337 MEDIUM
libde265 has an unbounded memory leak via orphaned slice headers in `read_slice_NAL`
CVSS 4.3
CVE-2026-55205 MEDIUM
Hermes WebUI < 0.51.468 - Resource Exhaustion via Unauthenticated OAuth Flow Endpoint
CVSS 5.3
CVE-2026-48990 MEDIUM
joserfc: b64=false RFC7797 JWS payloads bypass JWSRegistry payload-size limits during deserialization
CVSS 5.3
CVE-2026-47774 HIGH
Envoy vulnerable to HTTP/2 memory exhaustion via cookie header size bypass and HPACK amplification
CVSS 7.5
Details
Vulnerabilities 2,071
Exploit Likelihood High