VulnSea

CWE-770

CVEs classified under CWE-770, newest first.

588 CVEsRSS

GHSA-9mqv-5hh9-4cggMedium· 5.3
2mo ago

Node.js Adapter for Hono: Unauthenticated memory-leak DoS via aborted WebSocket handshake

Node.js Adapter for Hono: Unauthenticated memory-leak DoS via aborted WebSocket handshake

▾ Sunlithono · @hono/node-servervia GHSA
CVE-2026-59763Medium
2mo ago

Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads

Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.41%via GHSA
CVE-2026-42931Medium· 6.5
2mo ago

Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint

Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.53%via GHSA
CVE-2026-15588Medium· 5.3PoC
2mo ago

A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib

A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticat…

▾ TwilightRed Hat · glib2EPSS 0.48%via NVD
CVE-2026-55831High· 7.5
2mo ago

io.netty/netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing (CVE-2026-55831)

A flaw was found in Netty, a network application framework. A remote attacker, by sending a specially crafted SPDY/3.1 SETTINGS frame, could cause the SPDY SETTINGS decoder to create a large number of map entries. This excessive processing…

▾ TwilightRed Hat · Red Hat JBoss EAP 8.1 for RHEL 8EPSS 0.66%via CSAF
CVE-2026-12590Low· 3.7
2mo ago

body-parser vulnerable to denial of service when invalid limit value silently disables size enforcement

body-parser vulnerable to denial of service when invalid limit value silently disables size enforcement

▾ Sunlitbody-parser · body-parserEPSS 0.41%via GHSA
GHSA-f283-ghqc-fg79Medium· 5.3
2mo ago

Guzzle: Unbounded response cookies risk denial of service

Guzzle: Unbounded response cookies risk denial of service

▾ Sunlitguzzlehttp · guzzlehttp/guzzlevia GHSA
GHSA-jqh4-m9w3-8hp9Medium
2mo ago

Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`

Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`

▾ Sunlitaxios · axiosvia GHSA
CVE-2026-59870Medium· 5.3
2mo ago

js-yaml: Quadratic-complexity (O(n^2)) DoS via !!omap tag in YAML11_SCHEMA

js-yaml: Quadratic-complexity (O(n^2)) DoS via !!omap tag in YAML11_SCHEMA

▾ Sunlitjs-yaml · js-yamlEPSS 0.64%via GHSA
GHSA-pmv8-rq9r-6j72Medium
2mo ago

Axios: Deep formToJSON Key Recursion Can Cause Denial of Service

Axios: Deep formToJSON Key Recursion Can Cause Denial of Service

▾ Sunlitaxios · axiosvia GHSA
CVE-2025-71396None
2mo ago

SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 does not enforce a default execution-time limit on embedded JavaScript scripting functions when the scripting capability is explicitly enabled (via --allow-scripting or -…

SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 does not enforce a default execution-time limit on embedded JavaScript scripting functions when the scripting capability is explicitly enabled (via --allow-scripting or -…

▾ SunlitEPSS 0.55%via NVD
CVE-2026-50274High· 7.5
2mo ago

github.com/DataDog/dd-trace-go: Datadog dd-trace-go: Denial of Service via malicious baggage headers (CVE-2026-50274)

A flaw was found in Datadog dd-trace-go, a Go client library. A remote, unauthenticated attacker can exploit this vulnerability by sending a request with a specially crafted baggage header containing an arbitrarily large number of key-valu…

▾ TwilightRed Hat · github.com/DataDog/dd-trace-goEPSS 0.79%via CSAF
CVE-2026-44891High· 7.5
2mo ago

io.netty/netty-codec-stomp: Netty: Denial of Service vulnerability in STOMP decoder (CVE-2026-44891)

A flaw was found in Netty, a network application framework, specifically within the StompSubframeDecoder component. This vulnerability allows a remote attacker to cause a denial of service (DoS) by sending a large number of small headers. …

▾ TwilightRed Hat · Red Hat JBoss Enterprise Application Platform 7EPSS 0.73%via CSAF
CVE-2026-13585High· 8.2PoC
2mo ago

Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Control Interface driver and ASUS Business Manager allow a local administrator to disclose sensitive …

Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Control Interface driver and ASUS Business Manager allow a local administrator to disclose sensitive …

▾ MidnightASUS · System Control Interface v3EPSS 0.16%via NVD
CVE-2026-50271High· 7.5
2mo ago

dd-trace-py: Improper parsing of W3C baggage headers may lead to DoS

dd-trace-py: Improper parsing of W3C baggage headers may lead to DoS

▾ Twilightddtrace · ddtraceEPSS 0.79%via OSV
CVE-2026-50272High· 7.5
2mo ago

dd-trace-js: Improper parsing of W3C baggage headers may lead to DoS

dd-trace-js: Improper parsing of W3C baggage headers may lead to DoS

▾ Twilightdd-trace · dd-traceEPSS 0.79%via GHSA
CVE-2026-50273High· 7.5
2mo ago

dd-trace-dotnet: Improper parsing of W3C baggage headers may lead to DoS

dd-trace-dotnet: Improper parsing of W3C baggage headers may lead to DoS

▾ TwilightDatadog · Datadog.TraceEPSS 0.79%via GHSA
CVE-2026-54464Medium
2mo ago

websocket-driver: Resource limit bypass via message compression

websocket-driver: Resource limit bypass via message compression

▾ Sunlitwebsocket-driver · websocket-driverEPSS 0.45%via GHSA
CVE-2026-54490Medium
2mo ago

websocket-driver: Resource limit bypass via message compression

websocket-driver: Resource limit bypass via message compression

▾ Sunlitwebsocket-driver · websocket-driverEPSS 0.45%via GHSA
CVE-2026-15711High· 7.5PoC
2mo ago

A vulnerability was found in libsoup's WebSocket frame parsing implementation

A vulnerability was found in libsoup's WebSocket frame parsing implementation. The library fails to validate length rules specified in RFC 6455 §5.5, which mandates that all WebSocket control frames (e.g., PING, PONG, CLOSE) contain a pa…

▾ MidnightRed Hat · libsoup3EPSS 0.74%via NVD
CVE-2026-50506High· 7.5
2mo ago

OData for ASP.NET and ASP.NET Core Denial of Service Vulnerability

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

▾ TwilightMicrosoft · AspNet.ODataEPSS 1.2%via CVEORG
CVE-2026-49788High· 7.5
2mo ago

HTTP/2 Denial of Service Vulnerability

Allocation of resources without limits or throttling in HTTP/2 allows an unauthorized attacker to deny service over a network.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 1.2%via CVEORG
CVE-2026-49787High· 7.5
2mo ago

HTTP.sys Denial of Service Vulnerability

Allocation of resources without limits or throttling in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 1.2%via CVEORG
CVE-2026-59886High· 7.5
2mo ago

pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values (CVE-2026-59886)

A remote attacker can exploit this by providing specially crafted BER/CER/DER-encoded ASN.1 data with a large exponent in the REAL value. When the application subsequently prints, logs, compares, or performs arithmetic on the decoded value…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream EUS (v.9.6)EPSS 0.62%via CSAF
CVE-2026-56170High· 7.5
2mo ago

ASP.NET Core Denial of Service Vulnerability

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

▾ TwilightMicrosoft · .NET 10.0EPSS 1.2%via CVEORG
CVE-2026-50648High· 7.5
2mo ago

.NET Framework Denial of Service Vulnerability

Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.

▾ TwilightMicrosoft · .NET 10.0EPSS 1.2%via CVEORG
CVE-2026-50525High· 7.5
2mo ago

.NET Denial of Service Vulnerability

Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.

▾ TwilightMicrosoft · .NET 10.0EPSS 1.2%via CVEORG
CVE-2026-50651High· 7.5
2mo ago

.NET Denial of Service Vulnerability

Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.

▾ TwilightMicrosoft · .NET 10.0EPSS 1.2%via CVEORG
CVE-2026-59200High· 7.5
2mo ago

Pillow: Pillow: Denial of service via crafted PDF stream (CVE-2026-59200)

A flaw was found in Pillow, a Python imaging library. A remote attacker could exploit a vulnerability in the PdfParser.PdfStream.decode() function when processing a crafted FlateDecode PDF stream. By providing a specially designed PDF file…

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.66%via CSAF
CVE-2026-59204High· 7.5
2mo ago

Pillow: Pillow: Denial of Service via crafted JPEG2000 image (CVE-2026-59204)

A flaw was found in Pillow, a Python imaging library. A remote attacker could exploit this vulnerability by providing a specially crafted JPEG2000 image file. Due to incorrect calculation of memory requirements for image tiles, processing …

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.66%via CSAF
CWE-770 vulnerabilities (CVEs) — page 13 · VulnSea