CWE-770
High likelihoodAllocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
2,071 vulnerabilities with CWE-770
CVE-2026-54024
MEDIUM
LibreChat: Incomplete Fix for CVE-2024-11171 — Conversation Import Multer Instance Missing File Size Limits
CVSS 6.5
CVE-2026-40211
MEDIUM
PowerDNS DNSdist - Denial of Service via Crafted DoH3 Queries
CVSS 5.3
CVE-2026-12760
MEDIUM
Denial-of-Service Vulnerability via Malformed IPv4 Fragmentation Handling in TP-Link Tapo C200
CVSS 6.5
CVE-2026-49851
HIGH
Mistune: Potential DoS via quadratic-time parsing in parse_link_text
CVSS 7.5
CVE-2026-54297
HIGH
Faraday NestedParamsEncoder < 1.10.6/2.14.3 - Stack Exhaustion DoS
CVSS 7.5
CVE-2026-11972
HIGH
Python Software Foundation CPython - Tarfile Opened in Streaming Mode Mishandles EOF
CVE-2026-46553
LOW
NocoDB: Attachment Size Limit Bypass via Upload-by-URL
CVE-2026-46551
MEDIUM
NocoDB: Missing File Size Enforcement in Upload-by-URL Allows Denial of Service via Disk Exhaustion
CVSS 6.5
CVE-2026-56324
HIGH
Capgo - Rate Limit Bypass via User-Controlled device_id Parameter
CVSS 8.2
CVE-2026-56255
MEDIUM
Capgo - Denial of Service via Unlimited Demo App Creation
CVSS 4.3
CVE-2026-48515
HIGH
MessagePack-CSharp: Multi-dimensional array formatters allocate from unchecked dimensions
CVSS 7.5
CVE-2026-48514
HIGH
MessagePack-CSharp: Unity unsafe blit formatter allocates from unbounded byte length
CVSS 7.5
CVE-2026-48510
HIGH
MessagePack-CSharp: LZ4 decompression allocates from unbounded declared output lengths
CVSS 7.5
CVE-2026-39904
MEDIUM
Gophish 0.12.1 Denial of Service via Office Document Upload
CVSS 6.5
CVE-2026-54285
MEDIUM
opentelemetry-js: Unbounded memory allocation in W3C Baggage propagation
CVSS 5.3
CVE-2026-54283
HIGH
Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS
CVSS 7.5
CVE-2026-54277
HIGH
AIOHTTP: C HTTP Parser Bypasses max_line_size for Fragmented Lines
CVSS 7.5
CVE-2026-54274
HIGH
AIOHTTP: Incomplete websocket frame payloads bypass memory limits
CVSS 7.5
CVE-2026-54273
HIGH
AIOHTTP: HTTP/1 Pipelined Requests Queue Without Limit
CVSS 7.5
CVE-2026-54270
MEDIUM
protobufjs: Memory amplification from preserved unknown fields in binary decode
CVSS 5.3
CVE-2026-42127
HIGH
Grafana pre-auth DoS through arbitrarily large input to public dashboard query handler
CVSS 7.5
CVE-2026-49337
MEDIUM
libde265 has an unbounded memory leak via orphaned slice headers in `read_slice_NAL`
CVSS 4.3
CVE-2026-55205
MEDIUM
Hermes WebUI < 0.51.468 - Resource Exhaustion via Unauthenticated OAuth Flow Endpoint
CVSS 5.3
CVE-2026-48990
MEDIUM
joserfc: b64=false RFC7797 JWS payloads bypass JWSRegistry payload-size limits during deserialization
CVSS 5.3
CVE-2026-47774
HIGH
Envoy vulnerable to HTTP/2 memory exhaustion via cookie header size bypass and HPACK amplification
CVSS 7.5
Details
Vulnerabilities
2,071
Exploit Likelihood
High