CWE-770

High likelihood

Allocation of Resources Without Limits or Throttling

Parent: CWE-400 - Uncontrolled Resource Consumption

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

2,071 vulnerabilities with CWE-770
CVE-2026-9675 HIGH
undici WebSocket client vulnerable to denial of service via cumulative fragment bypass
CVSS 7.5
CVE-2026-12151 HIGH
undici WebSocket client vulnerable to denial of service via fragment count bypass
CVSS 7.5
CVE-2026-48779 HIGH
ws: Memory exhaustion DoS from tiny fragments and data chunks
CVSS 7.5
CVE-2026-27869 MEDIUM
WEB SERVICE (HTTP) DENIAL OF SERVICE VIA SLOW HEADERS ON REGESTA SMART HD-PLC OF TELDAT
CVE-2026-48854 HIGH
Unbounded request body accumulation causes memory exhaustion in elixir-grpc/grpc
CVE-2026-48853 CRITICAL
Remote code execution and denial of service via unsafe Erlang term deserialization in elixir-grpc/grpc
CVE-2026-8683 MEDIUM
Overly long URLs crash the Mattermost Desktop App
CVSS 6.5
CVE-2026-53522 MEDIUM
Nezha Monitoring: Unbounded WebSocket Streams — Resource Exhaustion DoS
CVSS 6.5
CVE-2026-50560 MEDIUM
Netty susceptible to HTTP/2 Reset Attack with different on-the-wire signature
CVSS 5.3
CVE-2026-50011 HIGH
Netty has unbounded pre-allocation in RedisArrayAggregator from RESP array length
CVSS 7.5
CVE-2026-48748 HIGH
Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion
CVSS 7.5
CVE-2026-46340 HIGH
Netty: SCTP reassembly nests buffers without bound
CVSS 7.5
CVE-2026-45416 HIGH
Netty: SNI handler pre-allocates up to 16 MiB from nine attacker bytes
CVSS 7.5
CVE-2026-49347 MEDIUM
Quest Bot: Ticket creation has no per-user open-ticket limit or cooldown
CVE-2026-44890 HIGH
Netty has Unbounded Direct Memory Consumption in its RedisDecoder
CVSS 7.5
CVE-2026-44250 HIGH
Netty: Memory Exhaustion in RedisArrayAggregator due to Deeply Nested Arrays
CVSS 7.5
CVE-2026-53781 MEDIUM
Summarize < 0.17.0 Disk Exhaustion via Uncapped Media Download
CVSS 4.3
CVE-2026-45802 MEDIUM
FPDI: Memory Exhaustion and Endless Loop in FPDI leads to Denial of Service
CVE-2026-44488 HIGH
Axios: Allocation of Resources Without Limits or Throttling in axios
CVSS 7.5
CVE-2026-7250 HIGH
Allocation of Resources Without Limits or Throttling in GitLab
CVSS 7.5
CVE-2026-53423 MEDIUM
Unauthenticated denial-of-service via BEAM atom table exhaustion in membrane_mp4_plugin
CVE-2026-1500 MEDIUM
Allocation of Resources Without Limits or Throttling in GitLab
CVSS 6.5
CVE-2026-5497 HIGH
Unbounded Frame Count in video/jpeg Base64 Data URL Processing Leads to OOM DoS in vllm-project/vllm
CVSS 7.5
CVE-2026-53460 HIGH
ImageMagick: Policy Bypass can trigger out-of-Memory condition
CVSS 7.5
CVE-2026-46702 HIGH
Russh: Post-decompression SSH packet size was not bounded, allowing remote oversized compressed packets
CVSS 7.5
Details
Vulnerabilities 2,071
Exploit Likelihood High