CWE-789

Memory Allocation with Excessive Size Value

Parent: CWE-770 - Allocation of Resources Without Limits or Throttling

The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.

187 vulnerabilities with CWE-789
CVE-2026-2456 MEDIUM
Denial of Service via Unbounded Memory Allocation in Integration Actions
CVSS 5.3
CVE-2026-26246 MEDIUM
Memory Exhaustion via Malformed PSD File Upload
CVSS 4.3
CVE-2026-25780 MEDIUM
Memory Exhaustion via Malformed DOC File Upload
CVSS 4.3
CVE-2026-29776 LOW
FreeRDP <3.24.0 - Memory Corruption
CVSS 3.1
CVE-2026-28253 HIGH
Trane Tracer SC/SC+/Concierge - DoS
CVSS 7.5
CVE-2026-27887 MEDIUM
Spin < 3.6.1, SpinKube < 0.6.2, containerd-shim-spin < 0.22.1 - Denial of Service via Unbounded Response Buffering
CVE-2026-27809 CRITICAL
psd-tools < 1.12.2 - Denial of Service via Malformed RLE-Compressed Image Data
CVSS 9.1
CVE-2026-20048 HIGH
Cisco NX-OS System Software in ACI Mode - Authenticated Denial of Service via SNMP Request Parsing
CVSS 7.7
CVE-2026-27204 MEDIUM
Wasmtime <24.0.6/36.0.6/40.0.4/41.0.4/42.0.0 - DoS
CVSS 6.5
CVE-2026-25899 HIGH
GoFiber v3 <3.1.0 - Deserialization
CVSS 7.5
CVE-2026-25985 HIGH
ImageMagick <7.1.2-15/<6.9.13-40 - DoS
CVSS 7.5
CVE-2026-25579 MEDIUM
Navidrome < 0.60.0 - Authenticated Denial of Service via Large Cover Art Size Parameter
CVSS 6.5
CVE-2026-22803 HIGH
SvelteKit 2.49.0-2.49.4 - Denial of Service via Form Remote Function Memory Exhaustion
CVSS 7.5
CVE-2026-22026 HIGH
CryptoLib < 1.4.3 - Denial of Service via Unbounded Memory Allocation in KMC Client
CVSS 7.5
CVE-2026-22188 MEDIUM
Panda3D <= 1.10.16 - Denial of Service via Unbounded Stack Allocation in deploy-stub
CVSS 5.5
CVE-2026-21452 HIGH
MessagePack for Java < 0.9.11 - Denial of Service via EXT32 Payload Length
CVSS 7.5
CVE-2025-71395 HIGH
SurrealDB before 2.2.2 Memory Exhaustion via string::replace
CVE-2025-54151 MEDIUM
Qsync Central 5.0.0.0-5.0.0.3 - Denial of Service via Uncontrolled Resource Consumption
CVSS 5.5
CVE-2025-54150 MEDIUM
Qsync Central 5.0.0.0-5.0.0.3 - Authenticated Denial of Service via Uncontrolled Resource Consumption
CVSS 5.5
CVE-2025-54149 MEDIUM
Qsync Central 5.0.0.0-5.0.0.3 - Authenticated Denial of Service via Uncontrolled Resource Consumption
CVSS 5.5
CVE-2025-62600 HIGH
eProsima Fast DDS <2.6.11, 2.7.0-2.14.5, 3.0.0-3.2.3, 3.3.0, 3.4.0-3.4.1 - Remote DoS via SPDP Packet Tampering
CVSS 8.6
CVE-2025-62599 HIGH
eProsima Fast DDS < 2.6.11, 2.7.0-2.14.5, 3.0.0-3.2.3, 3.3.0, 3.4.0 - Remote DoS via SPDP Packet Tampering
CVSS 8.6
CVE-2025-2668 MEDIUM
IBM Db2 11.5.0-11.5.9 - Authenticated Denial of Service via Crafted Query
CVSS 6.5
CVE-2025-66199 MEDIUM
OpenSSL 3.3.0-3.3.6 - Denial of Service via TLS 1.3 Certificate Compression
CVSS 5.9
CVE-2025-12983 LOW
GitLab 16.9-18.3.5, 18.4-18.4.3, 18.5-18.5.1 - Authenticated Denial of Service via Nested Markdown Formatting
CVSS 3.5
Details
Vulnerabilities 187