CWE-770
High likelihoodAllocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
2,071 vulnerabilities with CWE-770
CVE-2026-9675
HIGH
undici WebSocket client vulnerable to denial of service via cumulative fragment bypass
CVSS 7.5
CVE-2026-12151
HIGH
undici WebSocket client vulnerable to denial of service via fragment count bypass
CVSS 7.5
CVE-2026-48779
HIGH
ws: Memory exhaustion DoS from tiny fragments and data chunks
CVSS 7.5
CVE-2026-27869
MEDIUM
WEB SERVICE (HTTP) DENIAL OF SERVICE VIA SLOW HEADERS ON REGESTA SMART HD-PLC OF TELDAT
CVE-2026-48854
HIGH
Unbounded request body accumulation causes memory exhaustion in elixir-grpc/grpc
CVE-2026-48853
CRITICAL
Remote code execution and denial of service via unsafe Erlang term deserialization in elixir-grpc/grpc
CVE-2026-8683
MEDIUM
Overly long URLs crash the Mattermost Desktop App
CVSS 6.5
CVE-2026-53522
MEDIUM
Nezha Monitoring: Unbounded WebSocket Streams — Resource Exhaustion DoS
CVSS 6.5
CVE-2026-50560
MEDIUM
Netty susceptible to HTTP/2 Reset Attack with different on-the-wire signature
CVSS 5.3
CVE-2026-50011
HIGH
Netty has unbounded pre-allocation in RedisArrayAggregator from RESP array length
CVSS 7.5
CVE-2026-48748
HIGH
Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion
CVSS 7.5
CVE-2026-46340
HIGH
Netty: SCTP reassembly nests buffers without bound
CVSS 7.5
CVE-2026-45416
HIGH
Netty: SNI handler pre-allocates up to 16 MiB from nine attacker bytes
CVSS 7.5
CVE-2026-49347
MEDIUM
Quest Bot: Ticket creation has no per-user open-ticket limit or cooldown
CVE-2026-44890
HIGH
Netty has Unbounded Direct Memory Consumption in its RedisDecoder
CVSS 7.5
CVE-2026-44250
HIGH
Netty: Memory Exhaustion in RedisArrayAggregator due to Deeply Nested Arrays
CVSS 7.5
CVE-2026-53781
MEDIUM
Summarize < 0.17.0 Disk Exhaustion via Uncapped Media Download
CVSS 4.3
CVE-2026-45802
MEDIUM
FPDI: Memory Exhaustion and Endless Loop in FPDI leads to Denial of Service
CVE-2026-44488
HIGH
Axios: Allocation of Resources Without Limits or Throttling in axios
CVSS 7.5
CVE-2026-7250
HIGH
Allocation of Resources Without Limits or Throttling in GitLab
CVSS 7.5
CVE-2026-53423
MEDIUM
Unauthenticated denial-of-service via BEAM atom table exhaustion in membrane_mp4_plugin
CVE-2026-1500
MEDIUM
Allocation of Resources Without Limits or Throttling in GitLab
CVSS 6.5
CVE-2026-5497
HIGH
Unbounded Frame Count in video/jpeg Base64 Data URL Processing Leads to OOM DoS in vllm-project/vllm
CVSS 7.5
CVE-2026-53460
HIGH
ImageMagick: Policy Bypass can trigger out-of-Memory condition
CVSS 7.5
CVE-2026-46702
HIGH
Russh: Post-decompression SSH packet size was not bounded, allowing remote oversized compressed packets
CVSS 7.5
Details
Vulnerabilities
2,071
Exploit Likelihood
High