CWE-789

Memory Allocation with Excessive Size Value

Parent: CWE-770 - Allocation of Resources Without Limits or Throttling

The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.

122 vulnerabilities with CWE-789
CVE-2026-33524 HIGH
Zserio: Integer Overflow in BitStreamReader and Unbounded Memory Allocation in Deserialization
CVSS 7.5
CVE-2026-40894 MEDIUM
OpenTelemetry dotnet: Excessive memory allocation when parsing OpenTelemetry propagation headers
CVSS 5.3
CVE-2026-40891 MEDIUM
OpenTelemetry dotnet: Unbounded `grpc-status-details-bin` parsing in OTLP/gRPC retry handling
CVSS 5.3
CVE-2026-40182 MEDIUM
OpenTelemetry dotnet: OTLP exporter reads unbounded HTTP response bodies
CVSS 5.3
CVE-2026-41314 MEDIUM
pypdf: Manipulated FlateDecode image dimensions can exhaust RAM
CVSS 6.5
CVE-2026-41312 MEDIUM
pypdf: Manipulated FlateDecode predictor parameters can exhaust RAM
CVSS 6.5
CVE-2026-40303 HIGH
zrok allows unauthenticated DoS via unbounded memory allocation in striped session cookie parsing
CVSS 7.5
CVE-2026-35633 MEDIUM
OpenClaw < 2026.3.22 - Unbounded Memory Allocation via Remote Media Error Responses
CVSS 5.3
CVE-2026-35186 HIGH
Wasmtime has an improperly masked return value from `table.grow` with Winch compiler backend
CVSS 7.5
CVE-2026-39882 MEDIUM
OpenTelemetry-Go OTLP HTTP exporters read unbounded HTTP response bodies
CVSS 5.3
CVE-2026-24146 HIGH
Nvidia Triton Inference Server - Denial of Service
CVSS 7.5
CVE-2026-39312 HIGH
Pre-Auth EAP-TLS DoS on SoftEther VPN Developer Edition
CVSS 7.5
CVE-2026-35549 MEDIUM
MariaDB <11.4.10, 11.5-11.8.5, 12-12.2.1 - DoS
CVSS 6.5
CVE-2026-24030 MEDIUM
Unbounded memory allocation for DoQ and DoH3
CVSS 5.3
CVE-2026-24158 HIGH
Nvidia Triton Inference Server - Denial of Service
CVSS 7.5
CVE-2026-33174 HIGH
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
CVSS 7.5
CVE-2026-32941 MEDIUM
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports
CVSS 6.5
CVE-2026-26931 MEDIUM
Memory Allocation with Excessive Size Value in Metricbeat Leading to Denial of Service
CVSS 5.7
CVE-2026-32836 MEDIUM
mackron / dr_libs Excessive Memory Allocation in PICTURE Metadata Parsing
CVSS 6.2
CVE-2026-2456 MEDIUM
Denial of Service via Unbounded Memory Allocation in Integration Actions
CVSS 5.3
CVE-2026-26246 MEDIUM
Memory Exhaustion via Malformed PSD File Upload
CVSS 4.3
CVE-2026-25780 MEDIUM
Memory Exhaustion via Malformed DOC File Upload
CVSS 4.3
CVE-2026-29776 LOW
FreeRDP <3.24.0 - Memory Corruption
CVSS 3.1
CVE-2026-28253 HIGH
Trane Tracer SC/SC+/Concierge - DoS
CVSS 7.5
CVE-2026-27887 MEDIUM
Spin - DoS
Details
Vulnerabilities 122