CWE-770— Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.— MITRE CWE catalog
2,007 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-770page 32 of 41
- CVE-2025-8537MEDIUMCVSS 5.9EG 5.92025-08-05
A vulnerability, which was classified as problematic, was found in Axiomatic Bento4 up to 1.6.0-641. Affected is the function AP4_DataBuffer::SetDataSize of the file Mp4Decrypt.cpp of the component mp4decrypt. The manipulation leads to all…
- CVE-2025-8885MEDIUMCVSS 6.3EG 6.32025-08-12
Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcprov on All (API modules), Legion of the Bouncy Castle Inc. BC-FJA bc-fips on All allows Excessive Allocation. This vulnerabil…
- CVE-2025-8916MEDIUMCVSS 6.3EG 6.32025-08-13
Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcpkix on All (API modules), Legion of the Bouncy Castle Inc. BC Java bcprov on All (API modules), Legion of the Bouncy Castle I…
- CVE-2025-9177HIGHCVSS 7.7EG 7.72025-10-14
A denial-of-service security issue exists in the affected product and version. The security issue stems from a high number of requests sent to the web server. This could result in a web server crash however; this does not impact I/O contro…
- CVE-2025-9368HIGHCVSS 8.7EG 8.72025-12-09
A security issue exists within 432ES-IG3 Series A, which affects GuardLink® EtherNet/IP Interface, resulting in denial-of-service. A manual power cycle is required to recover the device.
- CVE-2025-9784HIGHCVSS 7.5EG 7.52025-09-02
A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server…
- CVE-2026-0398MEDIUMCVSS 5.3EG 5.32026-02-09
Crafted zones can lead to increased resource usage and crafted CNAME chains can lead to cache poisoning in Recursor.
- CVE-2026-0530MEDIUMCVSS 6.5EG 6.52026-01-13
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana Fleet can lead to Excessive Allocation (CAPEC-130) via a specially crafted request. This causes the application to perform redundant processing operations that contin…
- CVE-2026-0531MEDIUMCVSS 6.5EG 6.52026-01-13
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana Fleet can lead to Excessive Allocation (CAPEC-130) via a specially crafted bulk retrieval request. This requires an attacker to have low-level privileges equivalent t…
- CVE-2026-0543MEDIUMCVSS 6.5EG 6.52026-01-13
Improper Input Validation (CWE-20) in Kibana's Email Connector can allow an attacker to cause an Excessive Allocation (CAPEC-130) through a specially crafted email address parameter. This requires an attacker to have authenticated access w…
- CVE-2026-0897HIGHCVSS 7.5EG 7.52026-01-15
Allocation of Resources Without Limits or Throttling in the HDF5 weight loading component in Google Keras 3.0.0 through 3.13.0 on all platforms allows a remote attacker to cause a Denial of Service (DoS) through memory exhaustion and…
- CVE-2026-10533MEDIUMCVSS 5.0EG 5.02026-06-01
A flaw was found in OpenShift Container Platform. Completed pods with restartPolicy: Never do not count toward ResourceQuota pod limits, and Kubernetes events are not quota-scoped. A non-privileged user who can create pods in a namespace c…
- CVE-2026-10573HIGHCVSS 8.7EG 8.72026-07-14
A denial-of-service security issue exists in 1734 POINT I/O™ module. The security issue stems from improper handling of crafted CIP messages, which can cause the module to enter a faulted state. A restart is required to recover.
- CVE-2026-10740MEDIUMCVSS 5.3EG 5.32026-06-10
Unbounded memory allocation in the CRYPTO frame reassembler in s2n-quic before 1.8.2 may allow an unauthenticated remote actor to cause a denial of service (degraded availability) by sending crafted QUIC Initial packets. To remediate th…
- CVE-2026-1102MEDIUMCVSS 5.3EG 5.32026-01-22
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.3 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an unauthenticated user to create a denial of service condition by sending re…
- CVE-2026-11586HIGHCVSS 7.5EG 7.52026-07-03
By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound on memory allocation for unacknowledged frames, a malicious server can exhaust all available memory by flooding curl with rapid, sequential…
- CVE-2026-11622HIGHCVSS 7.5EG 7.52026-07-22
A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage. The attacker needs to be able to send queries faster than the resolver can perform validation. The incr…
- CVE-2026-11946HIGHCVSS 7.5EG 7.52026-07-02
An unauthenticated remote attacker can exhaust server memory via the GetEndpoints Discovery Service in open62541. The endpointUrl field of GetEndpointsRequest is not validated for length. An attacker can declare an arbitrarily large string…
- CVE-2026-11972HIGHCVSS 8.2EG 8.22026-06-23
When using the "tarfile" module with a file opened in "streaming mode" (mode="r|") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.
- CVE-2026-12151HIGHCVSS 7.5EG 7.52026-06-17
Impact: The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocket server can stream many small or empty continu…
- CVE-2026-1224MEDIUMCVSS 4.9EG 4.92026-01-26
Tanium addressed an uncontrolled resource consumption vulnerability in Discover.
- CVE-2026-12590MEDIUMCVSS 5.9EG 5.92026-07-09
Impact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an invalid limit option value such as an unparseable string or NaN, bytes.parse returns null and the request body size chec…
- CVE-2026-12707HIGHCVSS 7.5EG 7.52026-07-14
Summary Cloudflare quiche was discovered to be vulnerable to memory resource exhaustion due to unbounded queuing of post-handshake client migration events. Impact quiche supports the connection migration features described in Sect…
- CVE-2026-12760MEDIUMCVSS 6.5EG 6.52026-06-24
A denial-of-service (DoS) vulnerability has been identified in Tapo C200 v3 in the network packet handling logic due to improper handling of IPv4 fragmented packets. An unauthenticated adjacent attacker can send crafted packets to cause …
- CVE-2026-12818CRITICALCVSS 9.3EG 9.32026-06-30
Delta Electronics DVP12SE PLCs are susceptible to a resource allocation vulnerability without limits or throttling (CWE-770) within their Modbus TCP service.
- CVE-2026-13069MEDIUMCVSS 6.5EG 6.52026-07-22
An authenticated user can cause excessive CPU consumption or out-of-memory conditions on a MongoDB server by sending a crafted Queryable Encryption find payload containing an unvalidated field used to control an internal computation loop. …
- CVE-2026-13074MEDIUMCVSS 5.3EG 5.32026-07-22
An unauthenticated remote client can cause excessive CPU consumption on a MongoDB server by sending a specific combination of parameters to the awaitable hello command in exhaust mode. The server's handling of this combination results in a…
- CVE-2026-13075MEDIUMCVSS 6.5EG 6.52026-07-22
An authenticated user can cause the mongod process to be terminated by the operating system under memory pressure via the $rankFusion and $scoreFusion aggregation stages. The issue originates in the server's error-handling path and require…
- CVE-2026-13076MEDIUMCVSS 6.5EG 6.52026-07-22
An authenticated user can cause a {{mongod}} process to be terminated by the operating system under memory pressure by performing a specific data type conversion operation within MongoDB's aggregation framework. The behavior stems from dis…
- CVE-2026-13322LOWCVSS 3.8EG 3.82026-06-26
A flaw was found in KubeVirt's downward metrics virtio-serial server. The server reads guest requests using textproto.Reader.ReadLine(), which buffers input indefinitely until a newline character is received, with no length limit or read d…
- CVE-2026-13585HIGHCVSS 8.2EG 8.22026-07-15
Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Control Interface driver and ASUS Business Manager allow a local administrator to disclose sensitive in…
- CVE-2026-13698HIGHCVSS 7.5EG 7.52026-07-06
A memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers with a valid tls-crypt-v2 client key to potentially cause a denial of service
- CVE-2026-1387MEDIUMCVSS 6.5EG 6.52026-02-11
GitLab has remediated an issue in GitLab EE affecting all versions from 15.6 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an authenticated user to cause Denial of Service by uploading a malicious file a…
- CVE-2026-1402MEDIUMCVSS 6.5EG 6.52026-05-27
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an authenticated user to cause denial of service …
- CVE-2026-14257HIGHCVSS 7.5EG 7.52026-07-23
brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the number of results with a max option (default 100,000) but does not bound the length of each result string. By chaining…
- CVE-2026-14330MEDIUMCVSS 5.5EG 5.52026-07-01
Multiple unbounded alloca() calls in the PulseAudio protocol server.
- CVE-2026-14362MEDIUMCVSS 4.9EG 4.92026-07-08
HashiCorp memberlist before version 0.6.0 is vulnerable to a denial-of-service issue in its push/pull state handling that may allow an attacker with network access to the gossip port to exhaust memory on a receiving node and cause the proc…
- CVE-2026-1456MEDIUMCVSS 6.5EG 6.52026-02-11
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an unauthenticated user to cause denial of service through CPU exhaustion by submitting specially…
- CVE-2026-1458MEDIUMCVSS 6.5EG 6.52026-02-11
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.0 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an unauthenticated user to cause denial of service b…
- CVE-2026-1500MEDIUMCVSS 6.5EG 6.52026-06-11
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user to cause denial of service…
- CVE-2026-15007MEDIUMCVSS 5.7EG 5.72026-07-17
A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to cause service disruption by supplying a repository release notes configuration file containing deeply nested YAML. When rele…
- CVE-2026-1519HIGHCVSS 7.5EG 7.52026-03-25
If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU. Authoritative-only servers are generally unaffected, although there are circumstances where authoritative…
- CVE-2026-1526HIGHCVSS 7.5EG 7.52026-03-12
The undici WebSocket client is vulnerable to a denial-of-service attack via unbounded memory consumption during permessage-deflate decompression. When a WebSocket connection negotiates the permessage-deflate extension, the client decompres…
- CVE-2026-15588MEDIUMCVSS 5.3EG 5.32026-07-20
A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated…
- CVE-2026-15711HIGHCVSS 7.5EG 7.52026-07-14
A vulnerability was found in libsoup's WebSocket frame parsing implementation. The library fails to validate length rules specified in RFC 6455 §5.5, which mandates that all WebSocket control frames (e.g., PING, PONG, CLOSE) contain a pay…
- CVE-2026-15957HIGHCVSS 7.5EG 7.52026-07-21
Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. Uncontrolled recursion in the JSON, C…
- CVE-2026-1659HIGHCVSS 7.5EG 7.52026-05-14
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.0 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to cause denial of service by sending specially cr…
- CVE-2026-1660MEDIUMCVSS 6.5EG 6.52026-04-22
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.3 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that under certain conditions could have allowed an authenticated user to cause denial of service…
- CVE-2026-16756HIGHCVSS 7.5EG 7.52026-07-23
Missing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections a…
- CVE-2026-1718HIGHCVSS 7.5EG 7.52026-05-27
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service with a specially crafted query when autonomous transactions are enabled.
Map vulnerabilities like CWE-770 to your infrastructure
EchelonGraph correlates every CVE — across CWE-770 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →