CWE-770
Allocation of Resources Without Limits
MITRENo catalog description on file. The MITRE CWE site has the canonical reference.
Recent CVEs
showing 36 of 36- CVE-2026-53522Medium· 6.510 h ago
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.0.0 to before version 2.2.0, the Nezha dashboard exposes two endpoints that create long-lived WebSocket streams to monitored agen
- CVE-2026-41726—EPSS 0%10 h ago
In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector header
maven - CVE-2026-45416—EPSS 0%13 h ago
Netty: SNI handler pre-allocates up to 16 MiB from nine attacker bytes
maven - CVE-2026-46340—EPSS 0%13 h ago
Netty: SCTP reassembly nests buffers without bound
maven - CVE-2026-44488—EPSS 0%13 h ago
Allocation of Resources Without Limits or Throttling in Axios
npm - CVE-2026-50560—EPSS 0%16 h ago
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty HTTP/2 max header size handling produces an attack similar to HTTP/2 Rapid Reset. There is a s
- CVE-2026-48748High· 7.5EPSS 0%16 h ago
Netty is a network application framework for development of protocol servers and clients. Prior to version 4.2.15.Final, a memory exhaustion vulnerability in the Netty HTTP/3 codec allows the creation of an infinite number of blocked stream
- CVE-2026-50011High· 7.516 h ago
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, RedisArrayAggregator pre-allocates ArrayList with initial capacity equal to the RESP array element c
- CVE-2026-49347—16 h ago
Quest Bot is an opensource Discord Bot. Prior to version 1.1.8, any user who can access the ticket panel can repeatedly create new ticket channels. The latest release still creates a new database ticket and Discord channel for every complet
- CVE-2026-24720Medium· 6.5EPSS 0%19 h ago
An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or
- CVE-2026-45802—EPSS 0%1 d ago
FPDI is a collection of PHP classes that facilitate reading pages from existing PDF documents and using them as templates in FPDF. Prior to version 2.6.7, an attacker can upload a small, malicious PDF file that will cause the server-side sc
- CVE-2026-53781Medium· 4.3EPSS 0%1 d ago
Summarize before 0.17.0 contains a resource exhaustion vulnerability that allows remote attackers to cause disk exhaustion by serving media responses that bypass the enforced size limit through missing or misreported Content-Length headers,
- CVE-2026-42570High· 7.5EPSS 0%1 d ago
Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. From version 5.6.3 to before version 5.8.1, devalue.parse could, due to quirks in some JavaScript engines, be convi
npm - CVE-2026-53460High· 7.5EPSS 0%1 d ago
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-50 and 7.1.2-25, a missing check for maximum memory request in AcquireAlignedMemory could trigger an out-of-Memory condi
- CVE-2026-45031Medium· 5.3EPSS 0%1 d ago
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, due to a missing check in the PSD decoder it would be possible to bypass the list-length resource polic
- CVE-2026-7250High· 7.5EPSS 0%1 d ago
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an unauthenticated user to cause denial of servic
- CVE-2026-46702High· 7.5EPSS 0%1 d ago
russh: Post-decompression SSH packet size was not bounded, allowing remote oversized compressed packets
crates.io - CVE-2026-41007High· 7.5EPSS 0%1 d ago
Spring HATEOAS maintains an unbounded static cache of StringLinkRelation instances keyed on attacker-supplied strings. Affected versions: Spring HATEOAS 1.5.0 through 1.5.6; 2.3.0 through 2.3.4; 2.4.0 through 2.4.1; 2.5.0 through 2.5.2; 3.
- CVE-2026-53423—EPSS 0%1 d ago
Allocation of Resources Without Limits or Throttling vulnerability in membraneframework membrane_mp4_plugin allows unauthenticated denial-of-service via BEAM atom table exhaustion. The MP4 box header parser converts each 4-byte box name to
- CVE-2026-1500Medium· 6.5EPSS 0%1 d ago
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user to cause denial of service
- CVE-2026-46673—EPSS 0%1 d ago
Russh: Unchecked CryptoVec allocation and growth handling is reachable
crates.io - CVE-2026-10740Medium· 5.3EPSS 0%2 d ago
Unbounded memory allocation in the CRYPTO frame reassembler in s2n-quic before 1.8.2 may allow an unauthenticated remote actor to cause a denial of service (degraded availability) by sending crafted QUIC Initial packets. To remediate thi
- CVE-2026-41716High· 7.5EPSS 0%2 d ago
Spring Data's internal property-lookup cache accepts and permanently retains attacker-supplied strings as cache keys, allowing heap exhaustion through repeated requests. Affected versions: Spring Data Commons 2.7.0 through 2.7.19; 3.3.0 th
- CVE-2026-41851Medium· 5.3EPSS 0%3 d ago
Applications which accept user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack if the evaluation of a SpEL expression triggers unbounded cache growth. Affected versions: Spring F
- CVE-2026-49955Medium· 5.3EPSS 0%3 d ago
Hermes WebUI before version 0.51.270 contains a resource exhaustion vulnerability that allows unauthenticated remote attackers to degrade service availability by repeatedly calling the passkey options endpoint without completing assertion.
- CVE-2026-28237—EPSS 0%3 d ago
Unrestricted resource allocation in AMD uProf may be exploitable to consume excessive system resources, potentially leading to a loss of availability.
- CVE-2026-50589Medium· 5.3EPSS 0%3 d ago
In OpenStack Ironic 32 before 37.0.0, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC service and effect a service crash.
- CVE-2026-43973—EPSS 0%3 d ago
Uncontrolled Resource Consumption vulnerability in ninenines gun (gun_http module) allows a malicious server to exhaust client memory via unbounded HTTP/1.1 response buffering. In gun_http:handle/5, three clauses accumulate incoming TCP da
- CVE-2026-41710Medium· 5.9EPSS 0%3 d ago
An attacker can craft a large number of unique requests that trigger a failure, exhausting the capacity of the application-wide stateful retry cache. Once the cache is full, it permanently rejects any further updates, causing all later stat
- CVE-2026-10533Medium· 5.0EPSS 0%4 d ago
A flaw was found in OpenShift Container Platform. Completed pods with restartPolicy: Never do not count toward ResourceQuota pod limits, and Kubernetes events are not quota-scoped. A non-privileged user who can create pods in a namespace ca
- CVE-2026-36499Medium· 6.5EPSS 0%6 d ago
A missing upper-bound check in the udpif_set_threads() function of Open vSwitch v3.6.90 allows an attacker with OVSDB write access to request an excessive number of handler or revalidation threads. This can cause a denial of service (DoS) v
- CVE-2026-40898Medium· 5.3EPSS 0%7 d ago
quic-go: HTTP/3 QPACK Trailer Expansion Memory Exhaustion
go - CVE-2022-32206Medium· 6.5EPSS 3%24 d ago
curl/libcurl: HTTP compression denial of service
curl - CVE-2023-23916Medium· 6.5EPSS 0%24 d ago
curl/libcurl: HTTP multi-header compression denial of service
curl - CVE-2023-38039Medium· 7.5EPSS 14%2026-04-25
curl/libcurl: HTTP headers eat all memory
curl - CVE-2022-32205Low· 4.3EPSS 2%2026-04-25
curl/libcurl: Set-Cookie denial of service
curl
CWE catalog data sourced from MITRE. CVE associations come from NVD weakness mappings; some CVEs carry multiple CWEs.