CWE-789
Memory Allocation with Excessive Size Value
The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.
122 vulnerabilities with CWE-789
CVE-2026-33524
HIGH
Zserio: Integer Overflow in BitStreamReader and Unbounded Memory Allocation in Deserialization
CVSS 7.5
CVE-2026-40894
MEDIUM
OpenTelemetry dotnet: Excessive memory allocation when parsing OpenTelemetry propagation headers
CVSS 5.3
CVE-2026-40891
MEDIUM
OpenTelemetry dotnet: Unbounded `grpc-status-details-bin` parsing in OTLP/gRPC retry handling
CVSS 5.3
CVE-2026-40182
MEDIUM
OpenTelemetry dotnet: OTLP exporter reads unbounded HTTP response bodies
CVSS 5.3
CVE-2026-41314
MEDIUM
pypdf: Manipulated FlateDecode image dimensions can exhaust RAM
CVSS 6.5
CVE-2026-41312
MEDIUM
pypdf: Manipulated FlateDecode predictor parameters can exhaust RAM
CVSS 6.5
CVE-2026-40303
HIGH
zrok allows unauthenticated DoS via unbounded memory allocation in striped session cookie parsing
CVSS 7.5
CVE-2026-35633
MEDIUM
OpenClaw < 2026.3.22 - Unbounded Memory Allocation via Remote Media Error Responses
CVSS 5.3
CVE-2026-35186
HIGH
Wasmtime has an improperly masked return value from `table.grow` with Winch compiler backend
CVSS 7.5
CVE-2026-39882
MEDIUM
OpenTelemetry-Go OTLP HTTP exporters read unbounded HTTP response bodies
CVSS 5.3
CVE-2026-24146
HIGH
Nvidia Triton Inference Server - Denial of Service
CVSS 7.5
CVE-2026-39312
HIGH
Pre-Auth EAP-TLS DoS on SoftEther VPN Developer Edition
CVSS 7.5
CVE-2026-35549
MEDIUM
MariaDB <11.4.10, 11.5-11.8.5, 12-12.2.1 - DoS
CVSS 6.5
CVE-2026-24030
MEDIUM
Unbounded memory allocation for DoQ and DoH3
CVSS 5.3
CVE-2026-24158
HIGH
Nvidia Triton Inference Server - Denial of Service
CVSS 7.5
CVE-2026-33174
HIGH
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
CVSS 7.5
CVE-2026-32941
MEDIUM
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports
CVSS 6.5
CVE-2026-26931
MEDIUM
Memory Allocation with Excessive Size Value in Metricbeat Leading to Denial of Service
CVSS 5.7
CVE-2026-32836
MEDIUM
mackron / dr_libs Excessive Memory Allocation in PICTURE Metadata Parsing
CVSS 6.2
CVE-2026-2456
MEDIUM
Denial of Service via Unbounded Memory Allocation in Integration Actions
CVSS 5.3
CVE-2026-26246
MEDIUM
Memory Exhaustion via Malformed PSD File Upload
CVSS 4.3
CVE-2026-25780
MEDIUM
Memory Exhaustion via Malformed DOC File Upload
CVSS 4.3
CVE-2026-29776
LOW
FreeRDP <3.24.0 - Memory Corruption
CVSS 3.1
CVE-2026-28253
HIGH
Trane Tracer SC/SC+/Concierge - DoS
CVSS 7.5
CVE-2026-27887
MEDIUM
Spin - DoS
Details
Vulnerabilities
122