CWE-770— Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.— MITRE CWE catalog
2,455 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-770page 49 of 50
- CVE-2026-8469HIGHCVSS 8.2EG 8.22026-05-20
Allocation of Resources Without Limits or Throttling vulnerability in phenixdigital phoenix_storybook allows unauthenticated denial-of-service via BEAM atom table exhaustion. Multiple LiveView event handlers convert user-supplied event pa…
- CVE-2026-84775MEDIUMCVSS 5.3EG 5.32026-09-02
Unauthenticated Denial of Service Attack in Really Simple SSL <= 9.8.0 versions.
- CVE-2026-84776HIGHCVSS 7.5EG 7.52026-09-03
Unauthenticated Denial of Service Attack in MalCare Security <= 6.69 versions.
- CVE-2026-84778HIGHCVSS 7.5EG 7.52026-09-03
Unauthenticated Denial of Service Attack in Migrate Guru – Site Migration & Cloning <= 6.65 versions.
- CVE-2026-84780MEDIUMCVSS 5.3EG 5.32026-09-02
Unauthenticated Denial of Service Attack in WP Go Maps <= 10.1.08 versions.
- CVE-2026-8486HIGHCVSS 7.5EG 7.52026-05-20
Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation allows Flooding. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.
- CVE-2026-8488HIGHCVSS 7.5EG 7.52026-05-20
Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation allows Excessive Allocation. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.
- CVE-2026-84890MEDIUMCVSS 5.9EG 5.92026-09-04
undici's decompress interceptor decompresses response bodies according to the untrusted Content-Encoding header. While the number of content-encoding layers is capped, the total decompressed output size is unbounded and there is no configu…
- CVE-2026-85107MEDIUMCVSS 4.3EG 4.32026-09-03
A vulnerability was found in NousResearch hermes-agent 0.18.0. This vulnerability affects the function resourceBufferFromUrl of the file apps/desktop/electron/main.ts of the component Electron Main Process. Performing a manipulation result…
- CVE-2026-85447HIGHCVSS 7.5EG 7.52026-09-03
MOOS-IvP pRealm through version 24.8.1 accepts unbounded REALMCAST_REQ subscriptions without validating duration or variable list limits. Attackers can register long-lived pipeways with many variables to cause pRealm to generate excessive …
- CVE-2026-85448HIGHCVSS 7.5EG 7.52026-09-03
MOOS-IvP uFldShoreBroker through 24.8.1 fails to limit the number of claimed communities stored in parallel vectors within ShoreBroker::handleMailNodePing(). A single publisher can supply unbounded distinct community names to grow retained…
- CVE-2026-85449HIGHCVSS 7.5EG 7.52026-09-03
MOOS-IvP pMarineViewer through 24.8.1 fails to limit the number of tracked node identities from NODE_REPORT messages, allowing attackers to exhaust memory by supplying unbounded distinct node names. Attackers can publish crafted NODE_REPOR…
- CVE-2026-85450HIGHCVSS 7.5EG 7.52026-09-03
MOOS core-moos through 10.4.0 contains a denial of service vulnerability in the MOOSDB HTTP server that creates unbounded connections and threads without limits. Attackers can open many connections and send endless header data to exhaust s…
- CVE-2026-85501MEDIUMCVSS 5.3EG 5.32026-09-16
Novel vulnerabilities to launch algorithmic complexity attacks on DNSSEC have been researched under the term 'ReTrap'. These result in degradation of service when malicious zones are used to serve the algorithmic complexity vulnerabilities…
- CVE-2026-85581HIGHCVSS 7.5EG 7.52026-09-04
SiYuan before v3.8.2 contains a denial of service vulnerability in the unauthenticated /api/system/uiproc endpoint that accepts and retains attacker-controlled process identifiers without size limits or authentication. Attackers can send r…
- CVE-2026-85582MEDIUMCVSS 6.5EG 6.52026-09-04
SiYuan versions before v3.8.2 contain an unbounded session creation vulnerability in the publish-service Basic Auth handler that allows authenticated attackers to exhaust memory. Attackers can repeatedly authenticate with valid credentials…
- CVE-2026-85584HIGHCVSS 7.5EG 7.52026-09-04
SiYuan versions before v3.8.2 contain a denial of service vulnerability in the publish-service Basic Auth throttle that stores failed-attempt state using attacker-controlled usernames without enforcing capacity limits or eviction policies.…
- CVE-2026-85664HIGHCVSS 7.5EG 7.52026-09-04
Chroma 1.5.9 fails to validate maximum bounds on HNSW index parameters max_neighbors, ef_construction, and ef_search in collection-create requests. Unauthenticated attackers can supply arbitrarily large parameter values to exhaust server m…
- CVE-2026-85703MEDIUMCVSS 6.5EG 6.52026-09-04
A flaw has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Affected by this issue is the function getJailbreak of the file server/backend.py of the component Jailbreak Mode. Executing a manipulation…
- CVE-2026-86040HIGHCVSS 7.5EG 7.52026-09-17
libp2p is a JavaScript implementation of the libp2p networking stack. Prior to 11.0.26, @libp2p/floodsub accepts unauthenticated RPC frames on /floodsub/1.0.0 through PeerStreams.attachInboundStream in packages/floodsub/src/peer-streams.ts…
- CVE-2026-86075HIGHCVSS 7.5EG 7.52026-09-08
n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the OAuth Dynamic Client Registration endpoint bounded redirect_uris but accepted arbitrarily large client_name and grant_types values. An unauthenticated remo…
- CVE-2026-86452HIGHCVSS 7.5EG 7.52026-09-07
Affected versions of MISP permit unauthenticated or weakly constrained request paths to perform persistent work without adequate input bounds or rate limiting. The users/forgot password-reset endpoint accepted an attacker-controlled emai…
- CVE-2026-86513MEDIUMCVSS 5.3EG 5.32026-09-08
A security flaw has been discovered in java-json-tools jackson-coreutils 2.0. This vulnerability affects the function TreePointer.tokensFromInput of the file src/main/java/com/github/fge/jackson/jsonpointer/TreePointer.java of the componen…
- CVE-2026-8683MEDIUMCVSS 6.5EG 6.52026-06-15
Mattermost Desktop App versions <=6.1 5.5.13.0 fail to account for attempting to open extremely long URLs in the Mattermost Desktop App which allows a malicious server owner to crash the application via including a script to call window.op…
- CVE-2026-86892MEDIUMCVSS 5.5EG 5.52026-09-14
This issue was addressed with additional entitlement checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, visionOS 27. An app may be able to cause a denial-of-service.
- CVE-2026-87011HIGHCVSS 7.5EG 7.52026-09-09
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1, the unauthenticated POST /oauth/backchannel-logout handler in backend/open_webui/utils/oauth.py fetched the OIDC discovery docum…
- CVE-2026-87742HIGHCVSS 7.5EG 7.52026-09-17
A flaw was found in quarkus-websockets-next. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by streaming messages over a single connection faster than the application can process them. Due to unbounded messa…
- CVE-2026-87908HIGHCVSS 7.5EG 7.52026-09-11
multiparty is a Node.js library for parsing multipart/form-data request bodies. In versions from 2.1.0 up to but not including 4.3.1, the parser does not bound the amount of memory used while accumulating the headers of a single multipart …
- CVE-2026-88012MEDIUMCVSS 5.3EG 5.32026-09-10
Traefik is an open source HTTP reverse proxy and load balancer. From 2.8.2 until 2.11.56 and 3.7.12, HTTP/3 entrypoints do not apply entryPoints..transport.respondingTimeouts.readTimeout because the timeout is enforced on a TCP connection …
- CVE-2026-88878MEDIUMCVSS 5.3EG 5.32026-09-10
Traefik is an HTTP reverse proxy and load balancer. In versions >= v2.8.2 through <= v2.11.55 and >= v3.0.0 through <= v3.7.11, the entryPoints.<name>.transport.respondingTimeouts settings — notably readTimeout, which is enabled by defau…
- CVE-2026-90584MEDIUMCVSS 5.3EG 5.32026-09-13
A weakness has been identified in TooTallNate Java-WebSocket up to 1.6.1. The impacted element is the function processFrameContinuousAndNonFin of the file Draft_6455.java of the component Fragmentation Handler. Executing a manipulation can…
- CVE-2026-9064HIGHCVSS 7.5EG 7.52026-05-20
A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated attacker can send a specially crafted LDA…
- CVE-2026-90668HIGHCVSS 7.5EG 7.52026-09-13
The webserver in UnrealIRCd 6.0.5 through 6.2.6 before 6.2.7 does not limit the number of HTTP request headers, which allows remote attackers to cause a denial of service (memory consumption and unresponsive server) via an HTTP request wit…
- CVE-2026-91080HIGHCVSS 7.5EG 7.52026-09-14
webhook through 2.8.3 reads the entire request body into memory before evaluating trigger rules, allowing unauthenticated attackers to exhaust memory by sending oversized bodies. Attackers can send multi-gigabyte request bodies with invali…
- CVE-2026-91149HIGHCVSS 7.5EG 7.52026-09-18
A flaw was found in Cockpit. An unauthenticated remote attacker can exploit this vulnerability by initiating and sustaining numerous simultaneous connections to the `cockpit-tls` service. This forces the service to create an unbounded numb…
- CVE-2026-9140HIGHCVSS 8.7EG 8.72026-07-14
A denial-of-service security issue exists in the 1719-AENTR. The security issue stems from improper handling of a UDP unicast network storm, which causes the device to become overloaded and lose communication. A power cycle is required …
- CVE-2026-91970MEDIUMCVSS 6.5EG 6.52026-09-15
Vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the Planka migrator that fails to enforce aggregate memory budgets during migration jobs. Authenticated attackers can submit migration requests pointing to attack…
- CVE-2026-91987MEDIUMCVSS 6.5EG 6.52026-09-15
atomic-agents-stack before 1.1.0 contains a cost-guardrail bypass in the _estimate_batch_cost function that returns zero cost for unknown models not in the pricing table. Attackers can configure deployments with unknown model identifiers t…
- CVE-2026-91990HIGHCVSS 7.5EG 7.52026-09-15
Tornado before 6.5.8 contains a memory amplification vulnerability in parse_multipart_form_data that splits multipart data before validating the max_parts limit. Attackers can send crafted multipart requests with many parts to create large…
- CVE-2026-92003MEDIUMCVSS 6.9EG 6.92026-09-15
Affected versions of MISP do not consistently apply the existing authentication-failure logging throttle. Two API authentication failure branches wrote directly to the Log model: - API requests with no authentication key; - reques…
- CVE-2026-92063MEDIUMCVSS 6.5EG 6.52026-09-15
Denial-of-service in the Audio/Video component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
- CVE-2026-92077MEDIUMCVSS 6.5EG 6.52026-09-15
Denial-of-service in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
- CVE-2026-92078MEDIUMCVSS 6.5EG 6.52026-09-15
Denial-of-service in the Security component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
- CVE-2026-92915HIGHCVSS 7.3EG 7.32026-09-17
WWBN AVideo through commit e01e41ecc (no patched version available) contains a broken access control flaw in objects/userVerifyEmail.php. The script disables the login requirement ($global['ignoreUserMustBeLoggedIn'] = 1), takes users_id d…
- CVE-2026-92961HIGHCVSS 7.5EG 7.52026-09-17
vm2 before 3.11.6 fails to enforce bufferAllocLimit on ArrayBuffer, SharedArrayBuffer, and TypedArray constructors, allowing attackers to allocate arbitrary host memory. Attackers can bypass the buffer allocation cap by using these V8 intr…
- CVE-2026-93308MEDIUMCVSS 4.3EG 4.32026-09-17
A vulnerability was found in O-RAN-SC SMO OAM 2025-06-10. Affected by this vulnerability is an unknown functionality of the component VES Collector. Performing a manipulation results in allocation of resources. The attack may be initiated …
- CVE-2026-93309MEDIUMCVSS 4.3EG 4.32026-09-17
A vulnerability was determined in O-RAN-SC SMO OAM 2025-06-10. Affected by this issue is some unknown functionality of the component VES Collector. Executing a manipulation can lead to allocation of resources. The attack may be launched re…
- CVE-2026-93310MEDIUMCVSS 5.3EG 5.32026-09-18
A vulnerability was identified in O-RAN-SC SMO OAM 2025-06-10. This affects an unknown part of the component VES Collector. The manipulation leads to allocation of resources. Remote exploitation of the attack is possible. The exploit is pu…
- CVE-2026-93488HIGHCVSS 7.5EG 7.52026-09-18
A flaw was found in Netty. SpdySessionHandler accepts an unlimited number of concurrent remote-initiated streams because localConcurrentStreams defaults to Integer.MAX_VALUE and the handler provides no API to change it. A remote peer can o…
- CVE-2026-93491HIGHCVSS 7.5EG 7.52026-09-18
A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this vulnerability by pipelining HTTP/1.1 requests on a single connection and withholding reads. This action causes the methodOverflowQueue to grow…
Map vulnerabilities like CWE-770 to your infrastructure
EchelonGraph correlates every CVE — across CWE-770 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →