CWE-770
Allocation of Resources Without Limits or Throttling
Description
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-125 · CAPEC-130 · CAPEC-147 · CAPEC-197 · CAPEC-229 · CAPEC-230 · CAPEC-231 · CAPEC-469 · CAPEC-482 · CAPEC-486 · CAPEC-487 · CAPEC-488 · CAPEC-489 · CAPEC-490 · CAPEC-491 · CAPEC-493 · CAPEC-494 · CAPEC-495 · CAPEC-496 · CAPEC-528
CVEs mapped to this weakness (2,458)
page 10 of 123| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-87742 | Hig | 0.49 | 7.5 | 0.00 | Sep 17, 2026 | A flaw was found in quarkus-websockets-next. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by streaming messages over a single connection faster than the application can process them. Due to unbounded message buffering and a lack of read… | ||
| CVE-2026-1168 | Hig | 0.49 | 7.5 | 0.01 | Sep 16, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4.6 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an unauthenticated user to cause denial of service due to improper resource allocation… | ||
| CVE-2025-14871 | Hig | 0.49 | 7.5 | 0.01 | Sep 16, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4.6 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an unauthenticated user to cause denial of service due to improper resource allocation… | ||
| CVE-2026-13260 | Hig | 0.49 | 7.5 | 0.00 | Sep 14, 2026 | IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources. | ||
| CVE-2026-91080 | Hig | 0.49 | 7.5 | 0.01 | Sep 14, 2026 | webhook through 2.8.3 reads the entire request body into memory before evaluating trigger rules, allowing unauthenticated attackers to exhaust memory by sending oversized bodies. Attackers can send multi-gigabyte request bodies with invalid signatures to trigger out-of-memory… | ||
| CVE-2026-90668 | Hig | 0.49 | 7.5 | 0.00 | Sep 13, 2026 | The webserver in UnrealIRCd 6.0.5 through 6.2.6 before 6.2.7 does not limit the number of HTTP request headers, which allows remote attackers to cause a denial of service (memory consumption and unresponsive server) via an HTTP request with an unlimited number of headers, if a… | ||
| CVE-2026-57099 | Hig | 0.49 | 7.5 | 0.01 | Sep 8, 2026 | Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. | ||
| CVE-2026-82075 | Hig | 0.49 | 7.5 | 0.00 | Sep 8, 2026 | An uncontrolled resource consumption weakness exists in the request-handling path of the MongoDB sharded-cluster router process. A client that has network access to a router port and has not authenticated can supply connection-monitoring parameters that cause the server to… | ||
| CVE-2026-62649 | Hig | 0.49 | 7.5 | 0.00 | Sep 8, 2026 | A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The web server does not properly limit or manage system resources when processing a high volume of concurrent HTTP requests. This could allow an unauthenticated remote attacker to cause the entire… | ||
| CVE-2026-48888 | Hig | 0.49 | 7.5 | 0.00 | Sep 8, 2026 | Allocation of Resources Without Limits or Throttling vulnerability in Automattic WooCommerce allows HTTP DoS. This issue affects WooCommerce: from n/a before 11.1.0. | ||
| CVE-2026-84778 | Hig | 0.49 | 7.5 | 0.00 | Sep 3, 2026 | Unauthenticated Denial of Service Attack in Migrate Guru – Site Migration & Cloning <= 6.65 versions. | ||
| CVE-2026-84776 | Hig | 0.49 | 7.5 | 0.00 | Sep 3, 2026 | Unauthenticated Denial of Service Attack in MalCare Security <= 6.69 versions. | ||
| CVE-2026-71257 | Hig | 0.49 | 7.5 | 0.01 | Aug 31, 2026 | Apache Wicket enforces the upload limits configured on a form or upload field while parsing a multipart request with Apache Commons FileUpload. If the request body has already been consumed by another component, Commons FileUpload returns no items and Wicket falls back to… | ||
| CVE-2026-19873 | Hig | 0.49 | 7.5 | 0.01 | Aug 31, 2026 | HTML::FormFu versions through 2.08 for Perl allow resource exhaustion via an unbounded repeat count from the query string in Repeatable elements. When a Repeatable element has counter_name set, its process method reads the repeat count from the named query string parameter,… | ||
| CVE-2026-81624 | Hig | 0.49 | 7.5 | 0.00 | Aug 31, 2026 | Undertow is a flexible performant web server used in JBoss EAP and WildFly. A flaw was found in how Undertow handles WebSocket connections. Specifically, certain configuration limits like message buffer sizes and session timeouts cannot be adjusted and default to being… | ||
| CVE-2026-81285 | Hig | 0.49 | 7.5 | 0.00 | Aug 28, 2026 | Unauthenticated Denial of Service Attack in Smush Image Compression and Optimization <= 4.2.0 versions. | ||
| CVE-2026-59289 | Hig | 0.49 | 7.5 | 0.00 | Aug 27, 2026 | Spring for GraphQL's Spring Data pagination support resolves arguments of a scrollable query and forwards the client-supplied values to the underlying repository. An attacker can forge a malicious query for a Connection field that can exhaust application memory or place… | ||
| CVE-2026-5680 | Hig | 0.49 | 7.5 | 0.00 | Aug 27, 2026 | A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending specially crafted WebSocket messages with permessage-deflate negotiated. This could lead to excessive memory consumption due to the PerMessageDeflateFunction.largerBuffer() method using… | ||
| CVE-2026-30073 | Hig | 0.49 | 7.5 | 0.00 | Aug 27, 2026 | An issue in the NssaiAvailabilitySubscriptionCreate component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted POST request. | ||
| CVE-2026-30071 | Hig | 0.49 | 7.5 | 0.00 | Aug 27, 2026 | An issue in the RechargePut function of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input. |
- risk 0.49cvss 7.5epss 0.00
A flaw was found in quarkus-websockets-next. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by streaming messages over a single connection faster than the application can process them. Due to unbounded message buffering and a lack of read…
- risk 0.49cvss 7.5epss 0.01
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4.6 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an unauthenticated user to cause denial of service due to improper resource allocation…
- risk 0.49cvss 7.5epss 0.01
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4.6 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an unauthenticated user to cause denial of service due to improper resource allocation…
- risk 0.49cvss 7.5epss 0.00
IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.
- risk 0.49cvss 7.5epss 0.01
webhook through 2.8.3 reads the entire request body into memory before evaluating trigger rules, allowing unauthenticated attackers to exhaust memory by sending oversized bodies. Attackers can send multi-gigabyte request bodies with invalid signatures to trigger out-of-memory…
- risk 0.49cvss 7.5epss 0.00
The webserver in UnrealIRCd 6.0.5 through 6.2.6 before 6.2.7 does not limit the number of HTTP request headers, which allows remote attackers to cause a denial of service (memory consumption and unresponsive server) via an HTTP request with an unlimited number of headers, if a…
- risk 0.49cvss 7.5epss 0.01
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
- risk 0.49cvss 7.5epss 0.00
An uncontrolled resource consumption weakness exists in the request-handling path of the MongoDB sharded-cluster router process. A client that has network access to a router port and has not authenticated can supply connection-monitoring parameters that cause the server to…
- risk 0.49cvss 7.5epss 0.00
A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The web server does not properly limit or manage system resources when processing a high volume of concurrent HTTP requests. This could allow an unauthenticated remote attacker to cause the entire…
- risk 0.49cvss 7.5epss 0.00
Allocation of Resources Without Limits or Throttling vulnerability in Automattic WooCommerce allows HTTP DoS. This issue affects WooCommerce: from n/a before 11.1.0.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Denial of Service Attack in Migrate Guru – Site Migration & Cloning <= 6.65 versions.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Denial of Service Attack in MalCare Security <= 6.69 versions.
- risk 0.49cvss 7.5epss 0.01
Apache Wicket enforces the upload limits configured on a form or upload field while parsing a multipart request with Apache Commons FileUpload. If the request body has already been consumed by another component, Commons FileUpload returns no items and Wicket falls back to…
- risk 0.49cvss 7.5epss 0.01
HTML::FormFu versions through 2.08 for Perl allow resource exhaustion via an unbounded repeat count from the query string in Repeatable elements. When a Repeatable element has counter_name set, its process method reads the repeat count from the named query string parameter,…
- risk 0.49cvss 7.5epss 0.00
Undertow is a flexible performant web server used in JBoss EAP and WildFly. A flaw was found in how Undertow handles WebSocket connections. Specifically, certain configuration limits like message buffer sizes and session timeouts cannot be adjusted and default to being…
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Denial of Service Attack in Smush Image Compression and Optimization <= 4.2.0 versions.
- risk 0.49cvss 7.5epss 0.00
Spring for GraphQL's Spring Data pagination support resolves arguments of a scrollable query and forwards the client-supplied values to the underlying repository. An attacker can forge a malicious query for a Connection field that can exhaust application memory or place…
- risk 0.49cvss 7.5epss 0.00
A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending specially crafted WebSocket messages with permessage-deflate negotiated. This could lead to excessive memory consumption due to the PerMessageDeflateFunction.largerBuffer() method using…
- risk 0.49cvss 7.5epss 0.00
An issue in the NssaiAvailabilitySubscriptionCreate component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
- risk 0.49cvss 7.5epss 0.00
An issue in the RechargePut function of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.