VulnSea

CWE-770

CVEs classified under CWE-770, newest first.

588 CVEsRSS

CVE-2026-55497Medium· 6.5
1mo ago

Cloudreve is a self-hosted file management and sharing system

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the built-in thumbnail and avatar image decoders limit compressed file size but do not limit decoded pixel dimensions, allowing an authenticated user to subm…

▾ Sunlitcloudreve · github.com/cloudreve/Cloudreve/v4EPSS 0.53%via NVD
CVE-2026-67437High· 7.5
1mo ago

OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)

OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)

▾ TwilightOliveTin · github.com/OliveTin/OliveTinEPSS 0.64%via GHSA
CVE-2026-63119Medium· 6.2
1mo ago

MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)

MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)

▾ Sunlitmcp · mcpEPSS 0.18%via GHSA
CVE-2026-67430Medium· 5.3
1mo ago

MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood

MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood

▾ Sunlitmcp · mcpEPSS 0.51%via GHSA
CVE-2026-67432High· 7.5
1mo ago

MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport

MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport

▾ Twilightmcp · mcpEPSS 0.78%via GHSA
CVE-2026-54638High· 7.5
2mo ago

gotd/td is a T Telegram MTProto API client in Go

gotd/td is a T Telegram MTProto API client in Go. Prior to 0.145.1, proto.UnencryptedMessage.Decode in proto/unencrypted_message.go read attacker controlled dataLen from an unauthenticated MTProto unencrypted packet and allocated make([]…

▾ Twilightgotd · github.com/gotd/tdEPSS 0.63%via NVD
CVE-2026-54345Medium
2mo ago

GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS)

GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS)

▾ Sunlitgopacket · github.com/gopacket/gopacketEPSS 0.79%via OSV
CVE-2026-54332Medium
2mo ago

GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated remote DoS

GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated remote DoS

▾ Sunlitgopacket · github.com/gopacket/gopacketEPSS 0.79%via GHSA
CVE-2026-54609High· 8.6
2mo ago

QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding

QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding

▾ Twilightquietterminal · com.quietterminal:qti-neonEPSS 0.46%via GHSA
CVE-2026-61609High· 7.5
2mo ago

Pterodactyl's shared global rate-limit key on login and 2FA checkpoint enables unauthenticated panel-wide authentication lockout (DoS)

Pterodactyl's shared global rate-limit key on login and 2FA checkpoint enables unauthenticated panel-wide authentication lockout (DoS)

▾ Twilightpterodactyl · pterodactyl/panelEPSS 0.74%via GHSA
CVE-2026-17501Medium· 5.3
2mo ago

A flaw has been found in ggml-org llama.cpp e15efe0

A flaw has been found in ggml-org llama.cpp e15efe0. This vulnerability affects the function transform of the file common/json-schema-to-grammar.cpp of the component JSON-Schema-to-GBNF Conversion. This manipulation causes allocation of …

▾ SunlitEPSS 0.72%via NVD
CVE-2026-55685Medium· 6.5
2mo ago

react-router: @remix-run/server-runtime: React Router: Denial of Service via unauthenticated manifest endpoint requests (CVE-2026-55685)

A flaw was found in React Router. An unauthenticated attacker can send targeted requests to the manifest endpoint, leading to a denial of service (DoS). This can put a heavy load on the server, significantly slowing down response times and…

▾ SunlitRed Hat · Red Hat OpenShift AI 3.4EPSS 0.71%via CSAF
GHSA-6vch-q96h-7gc3High
2mo ago

etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline

etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline

▾ Twilightetcd · go.etcd.io/etcd/v3via GHSA
GHSA-7ppr-r889-mcf2High· 7.5
2mo ago

blaze: Unbounded WebSocket message aggregation in http4s-blaze-server

blaze: Unbounded WebSocket message aggregation in http4s-blaze-server

▾ Twilighthttp4s · org.http4s:http4s-blaze-server_2.13via GHSA
GHSA-fp43-vj7g-pg92High· 7.5
2mo ago

OmniFaces: Forged combined-resource IDs and related output/push boundaries

OmniFaces: Forged combined-resource IDs and related output/push boundaries

▾ Twilightomnifaces · org.omnifaces:omnifacesvia GHSA
CVE-2026-16756High· 7.5
2mo ago

Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service

Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service

▾ Twilightaws-smithy-http-server · aws-smithy-http-serverEPSS 0.75%via GHSA
CVE-2026-44907High· 7.5
2mo ago

react-server-dom: Denial of Service in Server Functions

react-server-dom: Denial of Service in Server Functions

▾ Twilightreact-server-dom-webpack · react-server-dom-webpackEPSS 0.60%via GHSA
CVE-2026-55575High
2mo ago

LiquidJS: `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforce

LiquidJS: `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforce

▾ Twilightliquidjs · liquidjsEPSS 0.52%via GHSA
GHSA-4w2j-m93h-cj5jHigh· 7.5
2mo ago

Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly

Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly

▾ Twilightquinn-proto · quinn-protovia GHSA
GHSA-rvhp-75f6-9jqhLow· 3.3
2mo ago

ImageMagick: Policy Bypass possible with matrix-backed operations

ImageMagick: Policy Bypass possible with matrix-backed operations

▾ SunlitMagick · Magick.NET-Q16-AnyCPUvia GHSA
CVE-2026-14257High· 7.5
2mo ago

brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function (CVE-2026-14257)

A flaw was found in brace-expansion. A remote attacker can exploit this vulnerability by providing specially crafted input to the expand() function, which can lead to excessive memory consumption. This can cause a denial of service (DoS) b…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 0.64%via CSAF
CVE-2026-25800High· 7.5
2mo ago

quinn: Quinn: Remote memory exhaustion via malformed QUIC stream fragments (CVE-2026-25800)

A flaw was found in Quinn, a Rust implementation of the QUIC transport protocol. A remote attacker can exploit this vulnerability by sending specially crafted QUIC stream fragments with many gaps. This can lead to high buffer overhead in t…

▾ TwilightRed Hat · quinn-protoEPSS 0.61%via CSAF
CVE-2026-58661Medium
2mo ago

n8n: Authenticated Users Can Exhaust Temporary Disk Storage via Data-Table File Uploads

n8n: Authenticated Users Can Exhaust Temporary Disk Storage via Data-Table File Uploads

▾ Sunlitn8n · n8nEPSS 0.39%via GHSA
CVE-2026-59942Medium
2mo ago

Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps

Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps

▾ Sunlitdompdf · dompdf/dompdfEPSS 0.90%via GHSA
CVE-2026-64646Medium
2mo ago

Next.js: Unbounded Server Action payload in Edge runtime

Next.js: Unbounded Server Action payload in Edge runtime

▾ Sunlitnext · nextEPSS 0.52%via GHSA
CVE-2026-47013Medium· 5.3
2mo ago

Vulnerability in Oracle Java SE (component: JavaFX)

Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u491. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compro…

▾ Sunlitoracle · jdkEPSS 0.41%via NVD
CVE-2026-55851High· 7.5
2mo ago

io.netty/netty-codec-haproxy: Netty codec-haproxy: Denial of Service via crafted PROXY protocol v2 message (CVE-2026-55851)

A flaw was found in Netty's codec-haproxy module. A remote attacker could exploit a vulnerability in the HAProxyMessageDecoder by sending a specially crafted PROXY protocol v2 message. This leads to unbounded buffer accumulation, causing a…

▾ TwilightRed Hat · OpenShift ServerlessEPSS 0.63%via CSAF
CVE-2026-56816High· 7.5
2mo ago

io.netty:netty-codec-http3: Netty: Denial of Service due to uncontrolled memory buffering in HTTP/3 (CVE-2026-56816)

A flaw was found in Netty. An unauthenticated remote attacker can exploit a vulnerability in Netty's `Http3FrameCodec` by sending specially crafted HTTP/3 reserved frames with excessive payload lengths. This can lead to uncontrolled memory…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.64%via CSAF
GHSA-r7wm-3cxj-wff9High
2mo ago

jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)

jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)

▾ Twilightfasterxml · com.fasterxml.jackson.core:jackson-corevia GHSA
GHSA-hrxh-6v49-42gfHigh
2mo ago

gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities

gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities

▾ Twilightgrpc · google.golang.org/grpcvia GHSA
CWE-770 vulnerabilities (CVEs) — page 12 · VulnSea