CWE-770— Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.— MITRE CWE catalog
2,455 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-770page 47 of 50
- CVE-2026-69374MEDIUMCVSS 6.5EG 6.52026-09-08
Allocation of resources without limits or throttling in Windows SMB Server allows an authorized attacker to deny service over a network.
- CVE-2026-6948MEDIUMCVSS 4.9EG 4.92026-05-04
Velociraptor versions prior to 0.76.4 contain a resource exhaustion vulnerability in the server's agent control channel. This allows a compromised or rogue Velociraptor client to crash the server via out-of-memory (OOM) by sending craft…
- CVE-2026-70399HIGHCVSS 8.7EG 8.72026-09-01
Allocation of Resources Without Limits or Throttling vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by opening and holding open a large number of connections. The max_clients op…
- CVE-2026-70455HIGHCVSS 7.5EG 7.52026-08-13
rsync 3.4.2 before 3.5.0 contains a denial of service vulnerability that allows a remote sender to exhaust system resources by specifying the --zt short alias for --compress-threads, which bypasses the refuse options directive's string ma…
- CVE-2026-70464HIGHCVSS 7.5EG 7.52026-08-13
rsync daemon 2.0.0 before 3.5.0 contains a denial of service vulnerability that allows unauthenticated remote attackers to exhaust daemon connection slots by stalling the handshake process before or after module selection without triggeri…
- CVE-2026-71054MEDIUMCVSS 6.5EG 6.52026-08-26
Vulnerability in Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 7u511. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Ora…
- CVE-2026-71219MEDIUMCVSS 4.7EG 4.72026-09-03
A stack overflow vulnerability was found in gfs2-utils. The hash table traversal code in metawalk.c uses alloca() with an exponentially-derived size from the untrusted on-disk di_depth field without bounds validation. A crafted GFS2 filesy…
- CVE-2026-71224MEDIUMCVSS 4.7EG 4.72026-09-03
A stack overflow vulnerability was found in gfs2-utils. The metadata walk code in metawalk.c uses alloca() with an untrusted inode height value from on-disk metadata without bounds validation, causing stack exhaustion and a denial of servi…
- CVE-2026-71257HIGHCVSS 7.5EG 7.52026-08-31
Apache Wicket enforces the upload limits configured on a form or upload field while parsing a multipart request with Apache Commons FileUpload. If the request body has already been consumed by another component, Commons FileUpload returns …
- CVE-2026-71310MEDIUMCVSS 5.9EG 5.92026-08-05
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.0, the shared HTTP CONNECT helper in lib/proxy/http.go parses proxy CONNECT responses with http.ReadResponse over a…
- CVE-2026-71314HIGHCVSS 7.5EG 7.52026-08-05
Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an unauthenticated attacker can use a server island v-for prop, including vforToArray and , to trigger unbounded SSR memory allocation until M…
- CVE-2026-71321HIGHCVSS 7.5EG 7.52026-08-05
Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, the internal island renderer endpoint `/__nuxt_island/...` decodes and hashes attacker-controlled JSON body input with destr and ohash before …
- CVE-2026-71408MEDIUMCVSS 5.3EG 5.32026-08-12
A allocation of resources without limits or throttling vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions may allow attacker to denial of service via <insert attack vector here>
- CVE-2026-71469HIGHCVSS 7.5EG 7.52026-08-12
A flaw was found in search-v2-api. An unauthenticated attacker can exploit this by sending requests with unique random bearer tokens. Each unique token creates a permanent entry in the unbounded tokenReviews cache, which is not properly cl…
- CVE-2026-71486MEDIUMCVSS 4.3EG 4.32026-08-17
vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the /v1/completions/derender and /v1/chat/completions/derender endpoints accept caller-supplied GenerateResponse objects whose generate_responses, choices,…
- CVE-2026-7250HIGHCVSS 7.5EG 7.52026-06-11
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an unauthenticated user to cause denial of servi…
- CVE-2026-72651MEDIUMCVSS 6.5EG 6.52026-08-13
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with read-only privileges to the alerting feature could submit a specially c…
- CVE-2026-72652MEDIUMCVSS 6.5EG 6.52026-09-01
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted request that causes excessive resource cons…
- CVE-2026-72653MEDIUMCVSS 6.5EG 6.52026-08-13
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user who is authorized to manage maintenance windows could submit a specially cra…
- CVE-2026-72659MEDIUMCVSS 6.5EG 6.52026-08-13
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A specially crafted, malformed payload submitted to a Kibana visualization feature by an authentic…
- CVE-2026-72667MEDIUMCVSS 6.5EG 6.52026-08-13
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). A specially crafted request submitted by an authenticated user with minimal privileges to a vali…
- CVE-2026-72674MEDIUMCVSS 6.5EG 6.52026-08-13
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). A user-supplied list of document fields accepted by the Kibana Playground for RAG feature was ne…
- CVE-2026-72682MEDIUMCVSS 6.5EG 6.52026-09-01
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding only low, read-level Agent Builder privileges could submit a speci…
- CVE-2026-72684MEDIUMCVSS 6.5EG 6.52026-08-13
A flaw in Elasticsearch allows an authenticated user holding only read privileges to submit a small search request containing a crafted user-supplied input. Processing that input causes a specific internal component to allocate memory with…
- CVE-2026-72838MEDIUMCVSS 6.5EG 6.52026-08-14
FileBrowser versions before 2.63.19 fail to enforce the declared Upload-Length in the TUS resumable-upload PATCH endpoint, allowing authenticated users to write arbitrary data to disk. Attackers can send oversized request bodies that excee…
- CVE-2026-72888MEDIUMCVSS 6.5EG 6.52026-08-16
Net::OAuth versions before 0.32 for Perl allow memory exhaustion via unbounded caching of failed module loads in smart_require. smart_require stores results in a process-global hash with no bound and no eviction, and keeps an entry for ev…
- CVE-2026-72914HIGHCVSS 7.5EG 7.52026-08-10
Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14, 4.6.4, and 4.7.0-beta.1, the administrative statistics endpoints handled by Api::V1::Admin::MeasuresController and Api::V1::Admin::Retenti…
- CVE-2026-72978MEDIUMCVSS 5.9EG 5.92026-09-08
Allocation of resources without limits or throttling in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.
- CVE-2026-73060HIGHCVSS 7.5EG 7.52026-08-16
Scriban versions from 3.0.0 through 7.2.5 contain a denial of service vulnerability in the ScriptRange.Multiply operator that bypasses LoopLimit when the left operand is a lazy sequence. Attackers can supply templates with array multiplica…
- CVE-2026-73062HIGHCVSS 7.5EG 7.52026-08-16
Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability in the array multiplication operator that allocates memory without enforcing LoopLimit or overflow-safe arithmetic checks. Attackers can supply a large integer …
- CVE-2026-73089HIGHCVSS 7.5EG 7.52026-08-11
Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, index.js retains every distinct `(queries, context)` result in cache and every parseQueries() AST in parseCache…
- CVE-2026-73108HIGHCVSS 7.5EG 7.52026-08-26
RustDesk versions before 1.4.7 contain an uncontrolled speculative memory allocation vulnerability in BytesCodec. Before authentication, the decoder trusts the payload length encoded in a four-byte frame header and reserves that amount bef…
- CVE-2026-73196MEDIUMCVSS 6.5EG 6.52026-08-20
A flaw was found in FreeIPA. A low-privilege authenticated user can exploit this vulnerability by submitting an oversized One-Time Password (OTP) key value. This oversized key is then decoded and re-encoded without proper size limits, cons…
- CVE-2026-73197HIGHCVSS 7.5EG 7.52026-08-20
A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by sending oversized form POST requests to the `/ipa/migration/migration.py` endpoint. This can force the migration handler to read attacker-con…
- CVE-2026-73198HIGHCVSS 7.5EG 7.52026-08-20
A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `/ipa/i18n_messages` endpoint by sending an arbitrarily large request body. This can cause the service to consume excessive memory, leading …
- CVE-2026-73214HIGHCVSS 8.2EG 8.22026-08-11
Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.16.0, dtls_server_input_handler() and create_new_connected_udp_socket() in src/apps/relay/dtls_listener.c retain OpenSSL dtls1_reassemble_fragment() state for …
- CVE-2026-73228MEDIUMCVSS 5.3EG 5.32026-08-11
Django REST framework is a toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's request.data parsing in rest_framework/request.py Request._parse() passes the underlying HttpRequest stream to JSONParser and FormParser for…
- CVE-2026-73493HIGHCVSS 7.5EG 7.52026-08-12
Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Prior to 0.23.18 and 1.0.0-M42, http4s-blaze-server aggregates fragments of an incoming WebSocket message with no limit on total size or fragment count…
- CVE-2026-73500HIGHCVSS 8.7EG 8.72026-08-12
etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a network attacker who can reach an etcd TLS listener can open many TCP connections and never send a ClientHello. In c…
- CVE-2026-73541HIGHCVSS 8.2EG 8.22026-08-19
Allocation of Resources Without Limits or Throttling in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet through concurrent sponsored payments, denying service to legitimate payers once it is empty. MPP.Me…
- CVE-2026-73565MEDIUMCVSS 5.3EG 5.32026-08-13
@hono/node-server allows running the Hono application on Node.js. From 2.0.0 until 2.0.10, a WebSocket upgrade request to an upgradeWebSocket route with a missing or malformed Sec-WebSocket-Key header causes src/websocket.ts to retain the …
- CVE-2026-73635HIGHCVSS 7.5EG 7.52026-08-15
Allocation of resources without limits or throttling vulnerability in Apache Struts. When no fixed locale is configured, the locale used for localized-text lookups is taken from the incoming request, allowing an unauthenticated remote clie…
- CVE-2026-73997HIGHCVSS 7.5EG 7.52026-08-18
Unauthenticated Denial of Service Attack in Starter Templates by Kadence WP <= 2.3.3 versions.
- CVE-2026-74039MEDIUMCVSS 6.5EG 6.52026-08-18
Wazuh 4.0.0 before 4.14.7 and 5.0.0-beta2 contain a denial of service vulnerability that allows authenticated attackers with allow_run_as enabled to exhaust CPU resources by submitting arbitrarily deeply nested JSON structures to the POST …
- CVE-2026-7427HIGHCVSS 7.5EG 7.52026-08-12
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an unauthenticated user to cause a denial of service…
- CVE-2026-74784HIGHCVSS 8.7EG 8.72026-08-16
Scriban before 7.2.0 contains a denial of service vulnerability in the array.insert_at function that allocates unbounded null entries without respecting LoopLimit or LimitToString constraints. Attackers can supply a large index parameter t…
- CVE-2026-74786MEDIUMCVSS 6.5EG 6.52026-08-16
Scriban before 7.0.0 (affected versions <= 6.6.0) contains a denial-of-service vulnerability in which the LimitToString safety limit (default 1MB) can be bypassed because ObjectToString resets the per-call length counter (_currentToStringL…
- CVE-2026-74788HIGHCVSS 7.5EG 7.52026-08-16
Scriban before 7.0.0 (affected versions <= 6.6.0) contains an uncontrolled memory allocation vulnerability in the string.pad_left and string.pad_right template functions, which perform no validation on the width parameter before delegating…
- CVE-2026-74835HIGHCVSS 8.7EG 8.72026-09-01
The inets application HTTP server httpd fails to enforce a configured body-size limit on chunked request. This issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.…
- CVE-2026-74836HIGHCVSS 8.7EG 8.72026-08-20
Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows an unauthenticated remote attacker to pin an unbounded number of HTTP/2 stream processes indefinitely via connection-level flow control. When a str…
Map vulnerabilities like CWE-770 to your infrastructure
EchelonGraph correlates every CVE — across CWE-770 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →