CWE-770
CVEs classified under CWE-770, newest first.
588 CVEsRSS
CVE-2026-55497Medium· 6.5Cloudreve is a self-hosted file management and sharing system
Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the built-in thumbnail and avatar image decoders limit compressed file size but do not limit decoded pixel dimensions, allowing an authenticated user to subm…
CVE-2026-67437High· 7.5OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)
OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)
CVE-2026-63119Medium· 6.2MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)
MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)
CVE-2026-67430Medium· 5.3MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood
MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood
CVE-2026-67432High· 7.5MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport
MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport
CVE-2026-54638High· 7.5gotd/td is a T Telegram MTProto API client in Go
gotd/td is a T Telegram MTProto API client in Go. Prior to 0.145.1, proto.UnencryptedMessage.Decode in proto/unencrypted_message.go read attacker controlled dataLen from an unauthenticated MTProto unencrypted packet and allocated make([]…
CVE-2026-54345MediumGoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS)
GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS)
CVE-2026-54332MediumGoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated remote DoS
GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated remote DoS
CVE-2026-54609High· 8.6QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
CVE-2026-61609High· 7.5Pterodactyl's shared global rate-limit key on login and 2FA checkpoint enables unauthenticated panel-wide authentication lockout (DoS)
Pterodactyl's shared global rate-limit key on login and 2FA checkpoint enables unauthenticated panel-wide authentication lockout (DoS)
CVE-2026-17501Medium· 5.3A flaw has been found in ggml-org llama.cpp e15efe0
A flaw has been found in ggml-org llama.cpp e15efe0. This vulnerability affects the function transform of the file common/json-schema-to-grammar.cpp of the component JSON-Schema-to-GBNF Conversion. This manipulation causes allocation of …
CVE-2026-55685Medium· 6.5react-router: @remix-run/server-runtime: React Router: Denial of Service via unauthenticated manifest endpoint requests (CVE-2026-55685)
A flaw was found in React Router. An unauthenticated attacker can send targeted requests to the manifest endpoint, leading to a denial of service (DoS). This can put a heavy load on the server, significantly slowing down response times and…
GHSA-6vch-q96h-7gc3Highetcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline
etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline
GHSA-7ppr-r889-mcf2High· 7.5blaze: Unbounded WebSocket message aggregation in http4s-blaze-server
blaze: Unbounded WebSocket message aggregation in http4s-blaze-server
GHSA-fp43-vj7g-pg92High· 7.5OmniFaces: Forged combined-resource IDs and related output/push boundaries
OmniFaces: Forged combined-resource IDs and related output/push boundaries
CVE-2026-16756High· 7.5Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
CVE-2026-44907High· 7.5react-server-dom: Denial of Service in Server Functions
react-server-dom: Denial of Service in Server Functions
CVE-2026-55575HighLiquidJS: `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforce
LiquidJS: `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforce
GHSA-4w2j-m93h-cj5jHigh· 7.5Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
GHSA-rvhp-75f6-9jqhLow· 3.3ImageMagick: Policy Bypass possible with matrix-backed operations
ImageMagick: Policy Bypass possible with matrix-backed operations
CVE-2026-14257High· 7.5brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function (CVE-2026-14257)
A flaw was found in brace-expansion. A remote attacker can exploit this vulnerability by providing specially crafted input to the expand() function, which can lead to excessive memory consumption. This can cause a denial of service (DoS) b…
CVE-2026-25800High· 7.5quinn: Quinn: Remote memory exhaustion via malformed QUIC stream fragments (CVE-2026-25800)
A flaw was found in Quinn, a Rust implementation of the QUIC transport protocol. A remote attacker can exploit this vulnerability by sending specially crafted QUIC stream fragments with many gaps. This can lead to high buffer overhead in t…
CVE-2026-58661Mediumn8n: Authenticated Users Can Exhaust Temporary Disk Storage via Data-Table File Uploads
n8n: Authenticated Users Can Exhaust Temporary Disk Storage via Data-Table File Uploads
CVE-2026-59942MediumDompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps
Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps
CVE-2026-64646MediumNext.js: Unbounded Server Action payload in Edge runtime
Next.js: Unbounded Server Action payload in Edge runtime
CVE-2026-47013Medium· 5.3Vulnerability in Oracle Java SE (component: JavaFX)
Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u491. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compro…
CVE-2026-55851High· 7.5io.netty/netty-codec-haproxy: Netty codec-haproxy: Denial of Service via crafted PROXY protocol v2 message (CVE-2026-55851)
A flaw was found in Netty's codec-haproxy module. A remote attacker could exploit a vulnerability in the HAProxyMessageDecoder by sending a specially crafted PROXY protocol v2 message. This leads to unbounded buffer accumulation, causing a…
CVE-2026-56816High· 7.5io.netty:netty-codec-http3: Netty: Denial of Service due to uncontrolled memory buffering in HTTP/3 (CVE-2026-56816)
A flaw was found in Netty. An unauthenticated remote attacker can exploit a vulnerability in Netty's `Http3FrameCodec` by sending specially crafted HTTP/3 reserved frames with excessive payload lengths. This can lead to uncontrolled memory…
GHSA-r7wm-3cxj-wff9Highjackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)
jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)
GHSA-hrxh-6v49-42gfHighgRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities