CWE-789

Memory Allocation with Excessive Size Value

Parent: CWE-770 - Allocation of Resources Without Limits or Throttling

The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.

187 vulnerabilities with CWE-789
CVE-2026-11946 HIGH
GetEndpoints Memory Exhaustion in open62541
CVSS 7.5
CVE-2026-33592 HIGH
FindServers Memory Exhaustion in open62541
CVSS 7.5
CVE-2026-53917 HIGH
Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Client, Apache ActiveMQ Broker: Unbounded memory allocation in OpenWire property unmarshalling
CVSS 7.5
CVE-2026-53916 HIGH
Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: Unbounded header buffer in STOMP NIO codec
CVSS 7.5
CVE-2026-50734 HIGH
Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ All: Pre-authentication OpenWire memory-allocation DoS during wire format negotiation
CVSS 7.5
CVE-2026-53428 MEDIUM
Unbounded memory allocation in highlight_lines range expansion in mdex
CVE-2026-54448 MEDIUM
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser
CVSS 6.5
CVE-2026-48502 HIGH
MessagePack-CSharp ReadDateTime - Stack Overflow Denial of Service
CVSS 7.5
CVE-2026-44967 MEDIUM
opentelemetry-cpp: OTLP HTTP exporters read unbounded HTTP response
CVSS 5.3
CVE-2026-47734 MEDIUM
Dulwich has unbounded memory allocation in receive-pack from crafted thin packs
CVSS 5.7
CVE-2026-10142 HIGH
kafka-python prior to 2.3.2 Denial of Service via Protocol Parser Frame Length
CVSS 7.5
CVE-2026-52759 MEDIUM
Ghidra < 12.1.1 - Denial of Service via Uncontrolled Memory Allocation in Mach-O Parser
CVSS 5.5
CVE-2026-52753 MEDIUM
Ghidra < 12.0.3 - Out-of-Memory in Rust Symbol Demangler via Malformed Symbol
CVSS 5.5
CVE-2026-49975 HIGH
Apache HTTP Server: mod_http2 denial of service
CVSS 7.5
CVE-2026-41178 MEDIUM
OpenTelemetry-Go's baggage parsing no longer caps raw header length
CVSS 5.3
CVE-2026-47319 MEDIUM
Samsung Open Source Rlottie - Memory Allocation with Excessive Size Value
CVSS 6.1
CVE-2026-9538 HIGH
Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header
CVSS 7.5
CVE-2026-5740 HIGH
Unauthenticated WebSocket binary frame causes denial of service in Mattermost Server
CVSS 7.5
CVE-2026-8485 MEDIUM
Uncontrolled Memory Allocation vulnerability in Progress Software MOVEit Automation
CVSS 5.9
CVE-2026-47313 MEDIUM
Samsung Open Source Escargot 590345cc6258317c5da850d846ce6baaf2afc2d3 - Excessive Memory Allocation
CVSS 5.5
CVE-2026-6340 MEDIUM
Mattermost 10.11.0-10.11.13 11.4.0-11.4.3 11.5.0-11.5.1 - Authenticated Denial of Service via 7zip Archive Processing
CVSS 4.3
CVE-2026-44375 HIGH
Nerdbank.MessagePack: Attacker-controlled stackalloc in DateTime decoding causes process-terminating StackOverflowException
CVSS 7.5
CVE-2026-42582 HIGH
Netty: HTTP/3 QPACK literal unbounded allocation
CVSS 7.5
CVE-2026-42946 MEDIUM
NGINX ngx_http_scgi_module and ngx_http_uwsgi_module vulnerability
CVSS 6.5
CVE-2026-42348 MEDIUM
open-telemetry opentelemetry-dotnet-contrib - OpAMP Client Reads Unbounded HTTP Response Bodies
CVSS 5.9
Details
Vulnerabilities 187