CWE-789

Memory Allocation with Excessive Size Value

Parent: CWE-770 - Allocation of Resources Without Limits or Throttling

The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.

187 vulnerabilities with CWE-789
CVE-2026-42189 HIGH
Russh: Pre-auth DoS via unbounded allocation in keyboard-interactive auth
CVSS 7.5
CVE-2026-42241 MEDIUM
ParquetSharp: Possible Stack Overflow When Reading a ParquetFile with Large Decimal Type Width
CVSS 5.3
CVE-2026-43868 MEDIUM
Apache Thrift: Rust implementation vulnerable to CVE-2020-13949 pattern
CVSS 5.3
CVE-2026-42154 HIGH
Prometheus: remote read endpoint allows denial of service via crafted snappy payload
CVSS 7.5
CVE-2026-42146 MEDIUM
CImg Library: Uncontrolled memory allocation via nb_colors field in _load_bmp
CVSS 5.5
CVE-2026-42440 HIGH
Apache OpenNLP: OOM DoS via Unbounded Array Allocation in AbstractModelReader
CVSS 7.5
CVE-2026-33524 HIGH
Zserio: Integer Overflow in BitStreamReader and Unbounded Memory Allocation in Deserialization
CVSS 7.5
CVE-2026-40894 MEDIUM
OpenTelemetry dotnet: Excessive memory allocation when parsing OpenTelemetry propagation headers
CVSS 5.3
CVE-2026-40891 MEDIUM
OpenTelemetry dotnet: Unbounded `grpc-status-details-bin` parsing in OTLP/gRPC retry handling
CVSS 5.3
CVE-2026-40182 MEDIUM
OpenTelemetry dotnet: OTLP exporter reads unbounded HTTP response bodies
CVSS 5.3
CVE-2026-41314 MEDIUM
pypdf: Manipulated FlateDecode image dimensions can exhaust RAM
CVSS 6.5
CVE-2026-41312 MEDIUM
pypdf: Manipulated FlateDecode predictor parameters can exhaust RAM
CVSS 6.5
CVE-2026-40303 HIGH
zrok allows unauthenticated DoS via unbounded memory allocation in striped session cookie parsing
CVSS 7.5
CVE-2026-35633 MEDIUM
OpenClaw < 2026.3.22 - Unbounded Memory Allocation via Remote Media Error Responses
CVSS 5.3
CVE-2026-35186 HIGH
Wasmtime Winch table.grow - Denial of Service
CVSS 7.5
CVE-2026-39882 MEDIUM
OpenTelemetry-Go OTLP HTTP exporters read unbounded HTTP response bodies
CVSS 5.3
CVE-2026-24146 HIGH
NVIDIA Triton Inference Server < 26.02 - Denial of Service via Large Output Count
CVSS 7.5
CVE-2026-39312 HIGH
Pre-Auth EAP-TLS DoS on SoftEther VPN Developer Edition
CVSS 7.5
CVE-2026-35549 MEDIUM
MariaDB <11.4.10, 11.5-11.8.5, 12-12.2.1 - DoS
CVSS 6.5
CVE-2026-24030 MEDIUM
Unbounded memory allocation for DoQ and DoH3
CVSS 5.3
CVE-2026-24158 HIGH
NVIDIA Triton Inference Server < 26.01 - Denial of Service via Large Compressed HTTP Payload
CVSS 7.5
CVE-2026-33174 HIGH
Rails Active Storage Proxy Mode - Range Request Denial of Service
CVSS 7.5
CVE-2026-32941 MEDIUM
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports
CVSS 6.5
CVE-2026-26931 MEDIUM
Memory Allocation with Excessive Size Value in Metricbeat Leading to Denial of Service
CVSS 5.7
CVE-2026-32836 MEDIUM
mackron / dr_libs Excessive Memory Allocation in PICTURE Metadata Parsing
CVSS 6.2
Details
Vulnerabilities 187