CWE-770— Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.— MITRE CWE catalog
2,455 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-770page 33 of 50
- CVE-2025-71411MEDIUMCVSS 5.3EG 5.32026-08-07
Broadcast control frames can disconnect multiple aircraft simultaneously leading to delayed clearances and air traffic controller overload. This type of attack can be carried out remotely over radio frequency.
- CVE-2025-7337MEDIUMCVSS 6.5EG 6.52025-09-12
An issue has been discovered in GitLab CE/EE affecting all versions from 7.8 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed an authenticated user with Developer-level access to cause a persistent denial o…
- CVE-2025-7449MEDIUMCVSS 6.5EG 6.52025-11-26
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that could have allowed an authenticated user with specific permissions to cause a denial of service c…
- CVE-2025-7737HIGHCVSS 8.6EG 8.62026-06-19
DoS Vulnerability in 10G iSCSI Interface of Hitachi Virtual Storage Platform. This issue affects Hitachi Virtual Storage Platform E990, E1090, E1090H: before DKCMAIN Ver.93-07-21-80/00-05, CHB(iSCSI) Ver.88-01-02-04, before DKCMAIN Ver.…
- CVE-2025-8014HIGHCVSS 7.5EG 7.52025-09-27
Denial of Service issue in GraphQL endpoints in Gitlab EE/CE affecting all versions from 11.10 prior to 18.2.7, 18.3 prior to 18.3.3, and 18.4 prior to 18.4.1 allows unauthenticated users to potentially bypass query complexity limits leadi…
- CVE-2025-8099HIGHCVSS 7.5EG 7.52026-02-11
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.8 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions, could have allowed an unauthenticated user to cause denial of service…
- CVE-2025-8396MEDIUMCVSS 6.9EG 6.92025-09-15
Insufficiently specific bounds checking on authorization header could lead to denial of service in the Temporal server on all platforms due to excessive memory allocation.This issue affects all platforms and versions of OSS Server prior to…
- CVE-2025-8537MEDIUMCVSS 5.9EG 5.92025-08-05
A vulnerability, which was classified as problematic, was found in Axiomatic Bento4 up to 1.6.0-641. Affected is the function AP4_DataBuffer::SetDataSize of the file Mp4Decrypt.cpp of the component mp4decrypt. The manipulation leads to all…
- CVE-2025-8885MEDIUMCVSS 6.3EG 6.32025-08-12
Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcprov on All (API modules), Legion of the Bouncy Castle Inc. BC-FJA bc-fips on All allows Excessive Allocation. This vulnerabil…
- CVE-2025-8916MEDIUMCVSS 6.3EG 6.32025-08-13
Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcpkix on All (API modules), Legion of the Bouncy Castle Inc. BC Java bcprov on All (API modules), Legion of the Bouncy Castle I…
- CVE-2025-9177HIGHCVSS 7.7EG 7.72025-10-14
A denial-of-service security issue exists in the affected product and version. The security issue stems from a high number of requests sent to the web server. This could result in a web server crash however; this does not impact I/O contro…
- CVE-2025-9368HIGHCVSS 8.7EG 8.72025-12-09
A security issue exists within 432ES-IG3 Series A, which affects GuardLink® EtherNet/IP Interface, resulting in denial-of-service. A manual power cycle is required to recover the device.
- CVE-2025-9784HIGHCVSS 7.5EG 7.52025-09-02
A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server…
- CVE-2026-0398MEDIUMCVSS 5.3EG 5.32026-02-09
Crafted zones can lead to increased resource usage and crafted CNAME chains can lead to cache poisoning in Recursor.
- CVE-2026-0530MEDIUMCVSS 6.5EG 6.52026-01-13
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana Fleet can lead to Excessive Allocation (CAPEC-130) via a specially crafted request. This causes the application to perform redundant processing operations that contin…
- CVE-2026-0531MEDIUMCVSS 6.5EG 6.52026-01-13
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana Fleet can lead to Excessive Allocation (CAPEC-130) via a specially crafted bulk retrieval request. This requires an attacker to have low-level privileges equivalent t…
- CVE-2026-0543MEDIUMCVSS 6.5EG 6.52026-01-13
Improper Input Validation (CWE-20) in Kibana's Email Connector can allow an attacker to cause an Excessive Allocation (CAPEC-130) through a specially crafted email address parameter. This requires an attacker to have authenticated access w…
- CVE-2026-0897HIGHCVSS 7.5EG 7.52026-01-15
Allocation of Resources Without Limits or Throttling in the HDF5 weight loading component in Google Keras 3.0.0 through 3.13.0 on all platforms allows a remote attacker to cause a Denial of Service (DoS) through memory exhaustion and…
- CVE-2026-10533MEDIUMCVSS 5.0EG 5.02026-06-01
A flaw was found in OpenShift Container Platform. Completed pods with restartPolicy: Never do not count toward ResourceQuota pod limits, and Kubernetes events are not quota-scoped. A non-privileged user who can create pods in a namespace c…
- CVE-2026-10573MEDIUMCVSS 6.3EG 6.32026-07-14
A denial-of-service security issue exists in 1734 POINT I/O™ module. The security issue stems from improper handling of crafted CIP messages, which can cause the module to enter a faulted state. A restart is required to recover.
- CVE-2026-10600MEDIUMCVSS 4.3EG 4.32026-07-27
Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to bound the time and resource consumption of server-side document content extraction which allows an authenticated user with file-upload pe…
- CVE-2026-10740MEDIUMCVSS 5.3EG 5.32026-06-10
Unbounded memory allocation in the CRYPTO frame reassembler in s2n-quic before 1.8.2 may allow an unauthenticated remote actor to cause a denial of service (degraded availability) by sending crafted QUIC Initial packets. To remediate th…
- CVE-2026-10832MEDIUMCVSS 5.9EG 5.92026-09-18
A flaw was found in the DERDecoder class within wildfly-elytron-asn1. A remote attacker can exploit this resource exhaustion vulnerability by sending a specially crafted DER (Distinguished Encoding Rules) payload. The decoder attempts to a…
- CVE-2026-1102HIGHCVSS 7.5EG 7.52026-01-22
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.3 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an unauthenticated user to create a denial of service condition by sending re…
- CVE-2026-11586HIGHCVSS 7.5EG 7.52026-07-03
By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound on memory allocation for unacknowledged frames, a malicious server can exhaust all available memory by flooding curl with rapid, sequential…
- CVE-2026-11622HIGHCVSS 7.5EG 7.52026-07-22
A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage. The attacker needs to be able to send queries faster than the resolver can perform validation. The incr…
- CVE-2026-1168HIGHCVSS 7.5EG 7.52026-09-16
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4.6 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an unauthenticated user to cause denial of service…
- CVE-2026-11897HIGHCVSS 7.5EG 7.52026-07-30
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability to cause the server to consume mem…
- CVE-2026-11946HIGHCVSS 7.5EG 7.52026-07-02
An unauthenticated remote attacker can exhaust server memory via the GetEndpoints Discovery Service in open62541. The endpointUrl field of GetEndpointsRequest is not validated for length. An attacker can declare an arbitrarily large string…
- CVE-2026-11972HIGHCVSS 8.2EG 8.22026-06-23
When using the "tarfile" module with a file opened in "streaming mode" (mode="r|") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.
- CVE-2026-11993MEDIUMCVSS 4.3EG 4.32026-09-14
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to properly enforce the limit of concurrent files being processed and handled failed files, which allows a user with permission to upload fi…
- CVE-2026-12151HIGHCVSS 7.5EG 7.52026-06-17
Impact: The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocket server can stream many small or empty continu…
- CVE-2026-1224MEDIUMCVSS 6.5EG 6.52026-01-26
Tanium addressed an uncontrolled resource consumption vulnerability in Discover.
- CVE-2026-12570MEDIUMCVSS 5.5EG 5.52026-08-10
A vulnerability in keras-team/keras versions <= 3.15.0 allows for a denial of service (DoS) attack when loading malicious .keras model files via the keras.models.load_model() function. The H5IOStore.__getitem__ method in keras/src/saving/s…
- CVE-2026-12590MEDIUMCVSS 5.9EG 5.92026-07-09
Impact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an invalid limit option value such as an unparseable string or NaN, bytes.parse returns null and the request body size chec…
- CVE-2026-12707HIGHCVSS 7.5EG 7.52026-07-14
Summary Cloudflare quiche was discovered to be vulnerable to memory resource exhaustion due to unbounded queuing of post-handshake client migration events. Impact quiche supports the connection migration features described in Sect…
- CVE-2026-12733HIGHCVSS 7.5EG 7.52026-07-30
IBM DataPower Gateway could allow a remote attacker to cause a denial of service due to improper resource limitations.
- CVE-2026-12760MEDIUMCVSS 6.5EG 6.52026-06-24
A denial-of-service (DoS) vulnerability has been identified in Tapo C200 v3 in the network packet handling logic due to improper handling of IPv4 fragmented packets. An unauthenticated adjacent attacker can send crafted packets to cause …
- CVE-2026-12818CRITICALCVSS 9.3EG 9.32026-06-30
Delta Electronics DVP12SE PLCs are susceptible to a resource allocation vulnerability without limits or throttling (CWE-770) within their Modbus TCP service.
- CVE-2026-13069MEDIUMCVSS 6.5EG 6.52026-07-22
An authenticated user can cause excessive CPU consumption or out-of-memory conditions on a MongoDB server by sending a crafted Queryable Encryption find payload containing an unvalidated field used to control an internal computation loop. …
- CVE-2026-13074MEDIUMCVSS 5.3EG 5.32026-07-22
An unauthenticated remote client can cause excessive CPU consumption on a MongoDB server by sending a specific combination of parameters to the awaitable hello command in exhaust mode. The server's handling of this combination results in a…
- CVE-2026-13075MEDIUMCVSS 6.5EG 6.52026-07-22
An authenticated user can cause the mongod process to be terminated by the operating system under memory pressure via the $rankFusion and $scoreFusion aggregation stages. The issue originates in the server's error-handling path and require…
- CVE-2026-13076MEDIUMCVSS 6.5EG 6.52026-07-22
An authenticated user can cause a {{mongod}} process to be terminated by the operating system under memory pressure by performing a specific data type conversion operation within MongoDB's aggregation framework. The behavior stems from dis…
- CVE-2026-13260HIGHCVSS 7.5EG 7.52026-09-14
IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.
- CVE-2026-13322LOWCVSS 3.8EG 3.82026-06-26
A flaw was found in KubeVirt's downward metrics virtio-serial server. The server reads guest requests using textproto.Reader.ReadLine(), which buffers input indefinitely until a newline character is received, with no length limit or read d…
- CVE-2026-13585HIGHCVSS 8.2EG 8.22026-07-15
Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Control Interface driver and ASUS Business Manager allow a local administrator to disclose sensitive in…
- CVE-2026-13586HIGHCVSS 7.5EG 7.52026-08-03
In Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS). This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.…
- CVE-2026-13698HIGHCVSS 7.5EG 7.52026-07-06
A memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers with a valid tls-crypt-v2 client key to potentially cause a denial of service
- CVE-2026-1376HIGHCVSS 7.5EG 7.52026-03-17
IBM i 7.6 could allow a remote attacker to cause a denial of service using failed authentication connections due to improper allocation of resources.
- CVE-2026-1387MEDIUMCVSS 6.5EG 6.52026-02-11
GitLab has remediated an issue in GitLab EE affecting all versions from 15.6 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an authenticated user to cause Denial of Service by uploading a malicious file a…
Map vulnerabilities like CWE-770 to your infrastructure
EchelonGraph correlates every CVE — across CWE-770 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →