CWE-770
Allocation of Resources Without Limits or Throttling
Description
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-125 · CAPEC-130 · CAPEC-147 · CAPEC-197 · CAPEC-229 · CAPEC-230 · CAPEC-231 · CAPEC-469 · CAPEC-482 · CAPEC-486 · CAPEC-487 · CAPEC-488 · CAPEC-489 · CAPEC-490 · CAPEC-491 · CAPEC-493 · CAPEC-494 · CAPEC-495 · CAPEC-496 · CAPEC-528
CVEs mapped to this weakness (2,485)
page 118 of 125| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-18362 | Med | 0.00 | 5.9 | 0.00 | Jul 30, 2026 | The IRIS web application in version 2.4.26 and possibly others does not protect its user authentication against brute-force attacks. | ||
| CVE-2026-16971 | Med | 0.00 | 5.9 | 0.00 | Jul 30, 2026 | The IRIS web application in version 2.4.26 and possibly others does not protect its MFA validation against brute-force attacks. | ||
| CVE-2026-15975 | Hig | 0.00 | 7.5 | 0.01 | Jul 29, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an unauthenticated user to cause a denial of service due to insufficient resource throttling… | ||
| CVE-2026-54609 | Hig | 0.00 | 8.6 | 0.00 | Jul 28, 2026 | QTI Neon is a minimal, game-agnostic, relay-based UDP multiplayer protocol library. In version 1.0.0, the relay's handleReconnectRequest forwards RECONNECT_REQUEST packets to the host without bounding them, so an unauthenticated client can drive relay-to-host amplification and… | ||
| CVE-2026-61609 | Hig | 0.00 | 7.5 | 0.01 | Jul 28, 2026 | Pterodactyl is a free, open-source game server management panel. From 1.7.0 until 1.13.0, the authentication rate limiter defined in RouteServiceProvider::configureRateLimiting() applied a single global bucket to the login and two-factor checkpoint endpoints instead of keying by… | ||
| CVE-2026-47483 | Hig | 0.00 | 8.2 | 0.01 | Jul 28, 2026 | NVIDIA DCGM Exporter for all platforms contains a vulnerability in the /debug/pprof endpoints, where an attacker could cause uncontrolled resource consumption by submitting concurrent unauthenticated profiling requests. A successful exploit of this vulnerability might lead to… | ||
| CVE-2026-8287 | Med | 0.00 | 4.3 | 0.00 | Jul 23, 2026 | Allocation of resources without limits or throttling vulnerability in BizimHesap Information Systems Industry and Trade Inc. Online Pre-Accounting Software allows Excessive Allocation. This issue affects Online Pre-Accounting Software: through 17072026. | ||
| CVE-2026-65650 | Med | 0.00 | 4.3 | 0.00 | Jul 22, 2026 | Elgg before 7.0.0 does not check image dimensions to prevent denial of service via a large avatar upload. | ||
| CVE-2026-11622 | Hig | 0.00 | 7.5 | 0.01 | Jul 22, 2026 | A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage. The attacker needs to be able to send queries faster than the resolver can perform validation. The increased memory usage can be orders of… | ||
| CVE-2026-15957 | Hig | 0.00 | 7.5 | 0.01 | Jul 21, 2026 | Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. Uncontrolled recursion in the JSON, CBOR, and XML deserializer functions… | ||
| CVE-2026-44907 | Hig | 0.00 | 7.5 | 0.01 | Jul 21, 2026 | A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack… | ||
| CVE-2026-53596 | Med | 0.00 | 5.3 | 0.00 | Jul 20, 2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the FreeScout helpdesk application does not enforce rate limiting on the file upload endpoint. Any user can flood the server with upload requests, leading to database… | ||
| CVE-2026-63750 | Med | 0.00 | 5.3 | 0.00 | Jul 20, 2026 | SurrealDB versions before 3.1.0 fail to apply the SURREAL_WEBSOCKET_MAX_MESSAGE_SIZE limit to anonymous /sql WebSocket connections, allowing attackers to buffer unbounded frames in the per-connection read buffer. Attackers can stream WebSocket frames larger than the configured… | ||
| CVE-2026-50272 | Hig | 0.00 | 7.5 | 0.01 | Jul 17, 2026 | dd-trace is the Datadog APM client for Node.js. Prior to 5.100.0, W3C baggage propagation in packages/dd-trace/src/baggage.js and packages/dd-trace/src/opentracing/propagation/text_map.js parsed incoming baggage HTTP headers without enforcing DD_TRACE_BAGGAGE_MAX_ITEMS or… | ||
| CVE-2026-50271 | Hig | 0.00 | 7.5 | 0.01 | Jul 17, 2026 | Datadog dd-trace-py is the Datadog Python APM client. Prior to 4.8.2, Datadog tracing libraries that implement W3C baggage propagation parse incoming baggage HTTP headers without enforcing DD_TRACE_BAGGAGE_MAX_ITEMS or DD_TRACE_BAGGAGE_MAX_BYTES limits on the extract path. A… | ||
| CVE-2026-48504 | Med | 0.00 | 5.3 | 0.00 | Jul 17, 2026 | OpenTelemetry Rust is the Rust OpenTelemetry implementation. In 0.32.0 and earlier, BaggagePropagator::extract_with_context in opentelemetry_sdk did not enforce W3C Baggage size limits before parsing an inbound baggage header, so a large attacker-controlled header could cause… | ||
| CVE-2026-50273 | Hig | 0.00 | 7.5 | 0.01 | Jul 17, 2026 | Datadog .NET Tracer is a client library for Datadog APM for .NET applications. Prior to 3.43.0, Datadog tracing libraries that implement W3C baggage propagation parse incoming baggage HTTP headers without enforcing DD_TRACE_BAGGAGE_MAX_ITEMS or DD_TRACE_BAGGAGE_MAX_BYTES on… | ||
| CVE-2026-15007 | Med | 0.00 | — | 0.01 | Jul 17, 2026 | A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to cause service disruption by supplying a repository release notes configuration file containing deeply nested YAML. When release notes were generated, the… | ||
| CVE-2026-62210 | Med | 0.00 | 6.5 | 0.00 | Jul 17, 2026 | OpenClaw versions before 2026.6.1 contain a denial of service vulnerability where remote media URLs can trigger slow-read attacks that exhaust gateway worker resources. Attackers with access to configured input paths can supply remote media URLs that consume gateway resources… | ||
| CVE-2026-21729 | Hig | 0.00 | 7.5 | 0.00 | Jul 16, 2026 | Loki queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy. |
- risk 0.00cvss 5.9epss 0.00
The IRIS web application in version 2.4.26 and possibly others does not protect its user authentication against brute-force attacks.
- risk 0.00cvss 5.9epss 0.00
The IRIS web application in version 2.4.26 and possibly others does not protect its MFA validation against brute-force attacks.
- risk 0.00cvss 7.5epss 0.01
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an unauthenticated user to cause a denial of service due to insufficient resource throttling…
- risk 0.00cvss 8.6epss 0.00
QTI Neon is a minimal, game-agnostic, relay-based UDP multiplayer protocol library. In version 1.0.0, the relay's handleReconnectRequest forwards RECONNECT_REQUEST packets to the host without bounding them, so an unauthenticated client can drive relay-to-host amplification and…
- risk 0.00cvss 7.5epss 0.01
Pterodactyl is a free, open-source game server management panel. From 1.7.0 until 1.13.0, the authentication rate limiter defined in RouteServiceProvider::configureRateLimiting() applied a single global bucket to the login and two-factor checkpoint endpoints instead of keying by…
- risk 0.00cvss 8.2epss 0.01
NVIDIA DCGM Exporter for all platforms contains a vulnerability in the /debug/pprof endpoints, where an attacker could cause uncontrolled resource consumption by submitting concurrent unauthenticated profiling requests. A successful exploit of this vulnerability might lead to…
- risk 0.00cvss 4.3epss 0.00
Allocation of resources without limits or throttling vulnerability in BizimHesap Information Systems Industry and Trade Inc. Online Pre-Accounting Software allows Excessive Allocation. This issue affects Online Pre-Accounting Software: through 17072026.
- risk 0.00cvss 4.3epss 0.00
Elgg before 7.0.0 does not check image dimensions to prevent denial of service via a large avatar upload.
- risk 0.00cvss 7.5epss 0.01
A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage. The attacker needs to be able to send queries faster than the resolver can perform validation. The increased memory usage can be orders of…
- risk 0.00cvss 7.5epss 0.01
Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. Uncontrolled recursion in the JSON, CBOR, and XML deserializer functions…
- risk 0.00cvss 7.5epss 0.01
A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack…
- risk 0.00cvss 5.3epss 0.00
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the FreeScout helpdesk application does not enforce rate limiting on the file upload endpoint. Any user can flood the server with upload requests, leading to database…
- risk 0.00cvss 5.3epss 0.00
SurrealDB versions before 3.1.0 fail to apply the SURREAL_WEBSOCKET_MAX_MESSAGE_SIZE limit to anonymous /sql WebSocket connections, allowing attackers to buffer unbounded frames in the per-connection read buffer. Attackers can stream WebSocket frames larger than the configured…
- risk 0.00cvss 7.5epss 0.01
dd-trace is the Datadog APM client for Node.js. Prior to 5.100.0, W3C baggage propagation in packages/dd-trace/src/baggage.js and packages/dd-trace/src/opentracing/propagation/text_map.js parsed incoming baggage HTTP headers without enforcing DD_TRACE_BAGGAGE_MAX_ITEMS or…
- risk 0.00cvss 7.5epss 0.01
Datadog dd-trace-py is the Datadog Python APM client. Prior to 4.8.2, Datadog tracing libraries that implement W3C baggage propagation parse incoming baggage HTTP headers without enforcing DD_TRACE_BAGGAGE_MAX_ITEMS or DD_TRACE_BAGGAGE_MAX_BYTES limits on the extract path. A…
- risk 0.00cvss 5.3epss 0.00
OpenTelemetry Rust is the Rust OpenTelemetry implementation. In 0.32.0 and earlier, BaggagePropagator::extract_with_context in opentelemetry_sdk did not enforce W3C Baggage size limits before parsing an inbound baggage header, so a large attacker-controlled header could cause…
- risk 0.00cvss 7.5epss 0.01
Datadog .NET Tracer is a client library for Datadog APM for .NET applications. Prior to 3.43.0, Datadog tracing libraries that implement W3C baggage propagation parse incoming baggage HTTP headers without enforcing DD_TRACE_BAGGAGE_MAX_ITEMS or DD_TRACE_BAGGAGE_MAX_BYTES on…
- risk 0.00cvss —epss 0.01
A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to cause service disruption by supplying a repository release notes configuration file containing deeply nested YAML. When release notes were generated, the…
- risk 0.00cvss 6.5epss 0.00
OpenClaw versions before 2026.6.1 contain a denial of service vulnerability where remote media URLs can trigger slow-read attacks that exhaust gateway worker resources. Attackers with access to configured input paths can supply remote media URLs that consume gateway resources…
- risk 0.00cvss 7.5epss 0.00
Loki queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy.