CWE-770
CVEs classified under CWE-770, newest first.
588 CVEsRSS
GHSA-9mqv-5hh9-4cggMedium· 5.3Node.js Adapter for Hono: Unauthenticated memory-leak DoS via aborted WebSocket handshake
Node.js Adapter for Hono: Unauthenticated memory-leak DoS via aborted WebSocket handshake
CVE-2026-59763MediumGitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads
CVE-2026-42931Medium· 6.5Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint
CVE-2026-15588Medium· 5.3PoCA denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib
A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticat…
CVE-2026-55831High· 7.5io.netty/netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing (CVE-2026-55831)
A flaw was found in Netty, a network application framework. A remote attacker, by sending a specially crafted SPDY/3.1 SETTINGS frame, could cause the SPDY SETTINGS decoder to create a large number of map entries. This excessive processing…
CVE-2026-12590Low· 3.7body-parser vulnerable to denial of service when invalid limit value silently disables size enforcement
body-parser vulnerable to denial of service when invalid limit value silently disables size enforcement
GHSA-f283-ghqc-fg79Medium· 5.3Guzzle: Unbounded response cookies risk denial of service
Guzzle: Unbounded response cookies risk denial of service
GHSA-jqh4-m9w3-8hp9MediumAxios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`
Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`
CVE-2026-59870Medium· 5.3js-yaml: Quadratic-complexity (O(n^2)) DoS via !!omap tag in YAML11_SCHEMA
js-yaml: Quadratic-complexity (O(n^2)) DoS via !!omap tag in YAML11_SCHEMA
GHSA-pmv8-rq9r-6j72MediumAxios: Deep formToJSON Key Recursion Can Cause Denial of Service
Axios: Deep formToJSON Key Recursion Can Cause Denial of Service
CVE-2025-71396NoneSurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 does not enforce a default execution-time limit on embedded JavaScript scripting functions when the scripting capability is explicitly enabled (via --allow-scripting or -…
SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 does not enforce a default execution-time limit on embedded JavaScript scripting functions when the scripting capability is explicitly enabled (via --allow-scripting or -…
CVE-2026-50274High· 7.5github.com/DataDog/dd-trace-go: Datadog dd-trace-go: Denial of Service via malicious baggage headers (CVE-2026-50274)
A flaw was found in Datadog dd-trace-go, a Go client library. A remote, unauthenticated attacker can exploit this vulnerability by sending a request with a specially crafted baggage header containing an arbitrarily large number of key-valu…
CVE-2026-44891High· 7.5io.netty/netty-codec-stomp: Netty: Denial of Service vulnerability in STOMP decoder (CVE-2026-44891)
A flaw was found in Netty, a network application framework, specifically within the StompSubframeDecoder component. This vulnerability allows a remote attacker to cause a denial of service (DoS) by sending a large number of small headers. …
CVE-2026-13585High· 8.2PoCAllocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Control Interface driver and ASUS Business Manager allow a local administrator to disclose sensitive …
Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Control Interface driver and ASUS Business Manager allow a local administrator to disclose sensitive …
CVE-2026-50271High· 7.5dd-trace-py: Improper parsing of W3C baggage headers may lead to DoS
dd-trace-py: Improper parsing of W3C baggage headers may lead to DoS
CVE-2026-50272High· 7.5dd-trace-js: Improper parsing of W3C baggage headers may lead to DoS
dd-trace-js: Improper parsing of W3C baggage headers may lead to DoS
CVE-2026-50273High· 7.5dd-trace-dotnet: Improper parsing of W3C baggage headers may lead to DoS
dd-trace-dotnet: Improper parsing of W3C baggage headers may lead to DoS
CVE-2026-54464Mediumwebsocket-driver: Resource limit bypass via message compression
websocket-driver: Resource limit bypass via message compression
CVE-2026-54490Mediumwebsocket-driver: Resource limit bypass via message compression
websocket-driver: Resource limit bypass via message compression
CVE-2026-15711High· 7.5PoCA vulnerability was found in libsoup's WebSocket frame parsing implementation
A vulnerability was found in libsoup's WebSocket frame parsing implementation. The library fails to validate length rules specified in RFC 6455 §5.5, which mandates that all WebSocket control frames (e.g., PING, PONG, CLOSE) contain a pa…
CVE-2026-50506High· 7.5OData for ASP.NET and ASP.NET Core Denial of Service Vulnerability
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
CVE-2026-49788High· 7.5HTTP/2 Denial of Service Vulnerability
Allocation of resources without limits or throttling in HTTP/2 allows an unauthorized attacker to deny service over a network.
CVE-2026-49787High· 7.5HTTP.sys Denial of Service Vulnerability
Allocation of resources without limits or throttling in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.
CVE-2026-59886High· 7.5pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values (CVE-2026-59886)
A remote attacker can exploit this by providing specially crafted BER/CER/DER-encoded ASN.1 data with a large exponent in the REAL value. When the application subsequently prints, logs, compares, or performs arithmetic on the decoded value…
CVE-2026-56170High· 7.5ASP.NET Core Denial of Service Vulnerability
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
CVE-2026-50648High· 7.5.NET Framework Denial of Service Vulnerability
Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-50525High· 7.5.NET Denial of Service Vulnerability
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-50651High· 7.5.NET Denial of Service Vulnerability
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-59200High· 7.5Pillow: Pillow: Denial of service via crafted PDF stream (CVE-2026-59200)
A flaw was found in Pillow, a Python imaging library. A remote attacker could exploit a vulnerability in the PdfParser.PdfStream.decode() function when processing a crafted FlateDecode PDF stream. By providing a specially designed PDF file…
CVE-2026-59204High· 7.5Pillow: Pillow: Denial of Service via crafted JPEG2000 image (CVE-2026-59204)
A flaw was found in Pillow, a Python imaging library. A remote attacker could exploit this vulnerability by providing a specially crafted JPEG2000 image file. Due to incorrect calculation of memory requirements for image tiles, processing …