CWE-789
Memory Allocation with Excessive Size Value
The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.
187 vulnerabilities with CWE-789
CVE-2026-42189
HIGH
Russh: Pre-auth DoS via unbounded allocation in keyboard-interactive auth
CVSS 7.5
CVE-2026-42241
MEDIUM
ParquetSharp: Possible Stack Overflow When Reading a ParquetFile with Large Decimal Type Width
CVSS 5.3
CVE-2026-43868
MEDIUM
Apache Thrift: Rust implementation vulnerable to CVE-2020-13949 pattern
CVSS 5.3
CVE-2026-42154
HIGH
Prometheus: remote read endpoint allows denial of service via crafted snappy payload
CVSS 7.5
CVE-2026-42146
MEDIUM
CImg Library: Uncontrolled memory allocation via nb_colors field in _load_bmp
CVSS 5.5
CVE-2026-42440
HIGH
Apache OpenNLP: OOM DoS via Unbounded Array Allocation in AbstractModelReader
CVSS 7.5
CVE-2026-33524
HIGH
Zserio: Integer Overflow in BitStreamReader and Unbounded Memory Allocation in Deserialization
CVSS 7.5
CVE-2026-40894
MEDIUM
OpenTelemetry dotnet: Excessive memory allocation when parsing OpenTelemetry propagation headers
CVSS 5.3
CVE-2026-40891
MEDIUM
OpenTelemetry dotnet: Unbounded `grpc-status-details-bin` parsing in OTLP/gRPC retry handling
CVSS 5.3
CVE-2026-40182
MEDIUM
OpenTelemetry dotnet: OTLP exporter reads unbounded HTTP response bodies
CVSS 5.3
CVE-2026-41314
MEDIUM
pypdf: Manipulated FlateDecode image dimensions can exhaust RAM
CVSS 6.5
CVE-2026-41312
MEDIUM
pypdf: Manipulated FlateDecode predictor parameters can exhaust RAM
CVSS 6.5
CVE-2026-40303
HIGH
zrok allows unauthenticated DoS via unbounded memory allocation in striped session cookie parsing
CVSS 7.5
CVE-2026-35633
MEDIUM
OpenClaw < 2026.3.22 - Unbounded Memory Allocation via Remote Media Error Responses
CVSS 5.3
CVE-2026-35186
HIGH
Wasmtime Winch table.grow - Denial of Service
CVSS 7.5
CVE-2026-39882
MEDIUM
OpenTelemetry-Go OTLP HTTP exporters read unbounded HTTP response bodies
CVSS 5.3
CVE-2026-24146
HIGH
NVIDIA Triton Inference Server < 26.02 - Denial of Service via Large Output Count
CVSS 7.5
CVE-2026-39312
HIGH
Pre-Auth EAP-TLS DoS on SoftEther VPN Developer Edition
CVSS 7.5
CVE-2026-35549
MEDIUM
MariaDB <11.4.10, 11.5-11.8.5, 12-12.2.1 - DoS
CVSS 6.5
CVE-2026-24030
MEDIUM
Unbounded memory allocation for DoQ and DoH3
CVSS 5.3
CVE-2026-24158
HIGH
NVIDIA Triton Inference Server < 26.01 - Denial of Service via Large Compressed HTTP Payload
CVSS 7.5
CVE-2026-33174
HIGH
Rails Active Storage Proxy Mode - Range Request Denial of Service
CVSS 7.5
CVE-2026-32941
MEDIUM
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports
CVSS 6.5
CVE-2026-26931
MEDIUM
Memory Allocation with Excessive Size Value in Metricbeat Leading to Denial of Service
CVSS 5.7
CVE-2026-32836
MEDIUM
mackron / dr_libs Excessive Memory Allocation in PICTURE Metadata Parsing
CVSS 6.2
Details
Vulnerabilities
187