CWE-789

Memory Allocation with Excessive Size Value

Parent: CWE-770 - Allocation of Resources Without Limits or Throttling

The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.

153 vulnerabilities with CWE-789
CVE-2026-44967 MEDIUM
opentelemetry-cpp: OTLP HTTP exporters read unbounded HTTP response
CVSS 5.3
CVE-2026-47734 MEDIUM
Dulwich has unbounded memory allocation in receive-pack from crafted thin packs
CVSS 5.7
CVE-2026-10142 HIGH
kafka-python prior to 2.3.2 Denial of Service via Protocol Parser Frame Length
CVSS 7.5
CVE-2026-52759 MEDIUM
Ghidra < 12.1.1 - Denial of Service via Uncontrolled Memory Allocation in Mach-O Parser
CVSS 5.5
CVE-2026-52753 MEDIUM
Ghidra < 12.0.3 - Out-of-Memory in Rust Symbol Demangler via Malformed Symbol
CVSS 5.5
CVE-2026-49975 HIGH
Apache HTTP Server: mod_http2 denial of service
CVSS 7.5
CVE-2026-41178 MEDIUM
OpenTelemetry-Go's baggage parsing no longer caps raw header length
CVSS 5.3
CVE-2026-47319 MEDIUM
Samsung Open Source Rlottie - Memory Allocation with Excessive Size Value
CVSS 6.1
CVE-2026-9538 HIGH
Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header
CVSS 7.5
CVE-2026-5740 HIGH
Unauthenticated WebSocket binary frame causes denial of service in Mattermost Server
CVSS 7.5
CVE-2026-8485 MEDIUM
Uncontrolled Memory Allocation vulnerability in Progress Software MOVEit Automation
CVSS 5.9
CVE-2026-47313 MEDIUM
Samsung Open Source Escargot 590345cc6258317c5da850d846ce6baaf2afc2d3 - Excessive Memory Allocation
CVSS 5.5
CVE-2026-6340 MEDIUM
Mattermost 10.11.0-10.11.13 11.4.0-11.4.3 11.5.0-11.5.1 - Authenticated Denial of Service via 7zip Archive Processing
CVSS 4.3
CVE-2026-44375 HIGH
Nerdbank.MessagePack: Attacker-controlled stackalloc in DateTime decoding causes process-terminating StackOverflowException
CVSS 7.5
CVE-2026-42582 HIGH
Netty: HTTP/3 QPACK literal unbounded allocation
CVSS 7.5
CVE-2026-42946 MEDIUM
NGINX ngx_http_scgi_module and ngx_http_uwsgi_module vulnerability
CVSS 6.5
CVE-2026-42348 MEDIUM
open-telemetry opentelemetry-dotnet-contrib - OpAMP Client Reads Unbounded HTTP Response Bodies
CVSS 5.9
CVE-2026-42189 HIGH
Russh: Pre-auth DoS via unbounded allocation in keyboard-interactive auth
CVSS 7.5
CVE-2026-42241 MEDIUM
ParquetSharp: Possible Stack Overflow When Reading a ParquetFile with Large Decimal Type Width
CVSS 5.3
CVE-2026-43868 MEDIUM
Apache Thrift: Rust implementation vulnerable to CVE-2020-13949 pattern
CVSS 5.3
CVE-2026-42154 HIGH
Prometheus: remote read endpoint allows denial of service via crafted snappy payload
CVSS 7.5
CVE-2026-42146 MEDIUM
CImg Library: Uncontrolled memory allocation via nb_colors field in _load_bmp
CVSS 5.5
CVE-2026-42440 HIGH
Apache OpenNLP: OOM DoS via Unbounded Array Allocation in AbstractModelReader
CVSS 7.5
CVE-2026-33524 HIGH
Zserio: Integer Overflow in BitStreamReader and Unbounded Memory Allocation in Deserialization
CVSS 7.5
CVE-2026-40894 MEDIUM
OpenTelemetry dotnet: Excessive memory allocation when parsing OpenTelemetry propagation headers
CVSS 5.3
Details
Vulnerabilities 153