VulnSea

CWE-770

CVEs classified under CWE-770, newest first.

588 CVEsRSS

CVE-2026-57080High· 7.5
2mo ago

Net::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustion via an uncapped peer-wire message-length prefix. The peer-wire framing in _process_messages trusts the 4-byte length prefix sent by a connected peer with no …

Net::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustion via an uncapped peer-wire message-length prefix. The peer-wire framing in _process_messages trusts the 4-byte length prefix sent by a connected peer with no …

▾ TwilightEPSS 0.49%via NVD
CVE-2026-49835Medium· 5.9
2mo ago

Sigstore Timestamp Authority has OOM due to unbounded metric label cardinality

Sigstore Timestamp Authority has OOM due to unbounded metric label cardinality

▾ Sunlitsigstore · github.com/sigstore/timestamp-authority/v2EPSS 0.74%via GHSA
CVE-2025-32423None
3mo ago

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.32, there is a DoS vulnerability in ExtractTextInformationBlock. Malicious users can amplify their in…

▾ SunlitEPSS 0.38%via NVD
GHSA-qh5x-rfwf-rvfvHigh· 7.5
3mo ago

Hysteria vulnerable to server crash when max_datagram_frame_size very small

Hysteria vulnerable to server crash when max_datagram_frame_size very small

▾ Twilightapernet · github.com/apernet/hysteriavia GHSA
GHSA-jqc5-2p7q-fqfcHigh· 7.5
3mo ago

Hysteria: http large header with sniff cause server DoS

Hysteria: http large header with sniff cause server DoS

▾ Twilightapernet · github.com/apernet/hysteriavia GHSA
CVE-2026-48990Medium· 5.3
3mo ago

joserfc: b64=false RFC7797 JWS payloads bypass JWSRegistry payload-size limits during deserialization

joserfc: b64=false RFC7797 JWS payloads bypass JWSRegistry payload-size limits during deserialization

▾ Sunlitjoserfc · joserfcEPSS 0.27%via OSV
GHSA-q6rr-fm2g-g5x8Medium
3mo ago

Scriban: array * int (ScriptArray<T>.TryEvaluate) bypasses LoopLimit — incomplete fix for GHSA-c875-h985-hvrc, missed sibling of GHSA-24c8-4792-22hx

Scriban: array * int (ScriptArray<T>.TryEvaluate) bypasses LoopLimit — incomplete fix for GHSA-c875-h985-hvrc, missed sibling of GHSA-24c8-4792-22hx

▾ SunlitScriban · Scribanvia GHSA
GHSA-rp72-5v5q-2446Low
3mo ago

@cardano402/mcp-server missing spending limits, LAN-exposed HTTP transport, and SSRF via catalog.server.url

@cardano402/mcp-server missing spending limits, LAN-exposed HTTP transport, and SSRF via catalog.server.url

▾ Sunlitcardano402 · @cardano402/mcp-servervia GHSA
CVE-2026-47067High
3mo ago

Hackney vulnerable to atom-table exhaustion via unrecognized URL schemes

Hackney vulnerable to atom-table exhaustion via unrecognized URL schemes

▾ Twilighthackney · hackneyEPSS 0.70%via GHSA
CVE-2026-53522Medium· 6.5
3mo ago

Nezha Monitoring: Unbounded WebSocket Streams — Resource Exhaustion DoS

Nezha Monitoring: Unbounded WebSocket Streams — Resource Exhaustion DoS

▾ Sunlitnezhahq · github.com/nezhahq/nezhaEPSS 0.41%via GHSA
CVE-2026-48504Medium· 5.3
3mo ago

opentelemetry_sdk has unbounded memory allocation in W3C Baggage propagation

opentelemetry_sdk has unbounded memory allocation in W3C Baggage propagation

▾ Sunlitopentelemetry_sdk · opentelemetry_sdkEPSS 0.42%via GHSA
CVE-2026-48510Medium· 7.5
3mo ago

MessagePack-CSharp: LZ4 decompression allocates from unbounded declared output lengths

MessagePack-CSharp: LZ4 decompression allocates from unbounded declared output lengths

▾ SunlitMessagePack · MessagePackEPSS 0.40%via GHSA
CVE-2026-48514Medium
3mo ago

MessagePack-CSharp: Unity unsafe blit formatter allocates from unbounded byte length

MessagePack-CSharp: Unity unsafe blit formatter allocates from unbounded byte length

▾ SunlitMessagePack · MessagePackEPSS 0.40%via GHSA
CVE-2026-48515Medium
3mo ago

MessagePack-CSharp: Multi-dimensional array formatters allocate from unchecked dimensions

MessagePack-CSharp: Multi-dimensional array formatters allocate from unchecked dimensions

▾ SunlitMessagePack · MessagePackEPSS 0.40%via GHSA
CVE-2026-53460High· 7.5
3mo ago

ImageMagick: Policy Bypass can Trigger an Out-of-Memory condition

ImageMagick: Policy Bypass can Trigger an Out-of-Memory condition

▾ TwilightMagick · Magick.NET-Q16-AnyCPUEPSS 0.63%via GHSA
GHSA-pvrg-q6jw-42p7High· 7.5
3mo ago

Duplicate Advisory: Traefik vulnerable to HTTP/2 request causing denial of service

Duplicate Advisory: Traefik vulnerable to HTTP/2 request causing denial of service

▾ Twilighttraefik · github.com/traefik/traefikvia GHSA
CVE-2026-11972None
3mo ago

When using the "tarfile" module with a file opened in "streaming mode" (mode="r|") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.

When using the "tarfile" module with a file opened in "streaming mode" (mode="r|") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.

▾ SunlitEPSS 0.71%via NVD
CVE-2023-54365High· 7.5
3mo ago

Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inherited from the Go standard library's HTTP/2 implementation (CVE-2023-44487 / CVE-2023-39325, the 'Rapid Reset' techniqu…

Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inherited from the Go standard library's HTTP/2 implementation (CVE-2023-44487 / CVE-2023-39325, the 'Rapid Reset' techniqu…

▾ Twilighttraefik · traefikEPSS 0.77%via NVD
CVE-2026-42127High· 7.5
3mo ago

The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads

The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of serv…

▾ Twilightgrafana · grafanaEPSS 0.43%via NVD
CVE-2026-54283High· 7.5
3mo ago

starlette: Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS (CVE-2026-54283)

A flaw was found in Starlette where the request.form() method silently ignores configured resource limits (max_fields and max_part_size) when parsing application/x-www-form-urlencoded data. An unauthenticated attacker can exploit this by s…

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.48%via CSAF
CVE-2026-49209Low
3mo ago

symfony/ux-live-component: Denial of service via unbounded batch action requests

symfony/ux-live-component: Denial of service via unbounded batch action requests

▾ Sunlitsymfony · symfony/ux-live-componentEPSS 0.56%via GHSA
GHSA-v52w-28xh-v562High
3mo ago

Kozou: Unauthenticated MCP HTTP server and bundled dev-stack hardening (DNS-rebinding, request-body limits, read-only reads, default network exposure)

Kozou: Unauthenticated MCP HTTP server and bundled dev-stack hardening (DNS-rebinding, request-body limits, read-only reads, default network exposure)

▾ Twilightkozou · kozouvia GHSA
CVE-2026-55205Medium· 5.3PoC
3mo ago

Hermes WebUI before 0.51.468 contains a resource exhaustion vulnerability in the unauthenticated POST /api/onboarding/oauth/start endpoint that allows unbounded accumulation of in-memory flow state and daemon threads

Hermes WebUI before 0.51.468 contains a resource exhaustion vulnerability in the unauthenticated POST /api/onboarding/oauth/start endpoint that allows unbounded accumulation of in-memory flow state and daemon threads. Attackers can send …

▾ Twilightnesquena · hermes-webuiEPSS 0.52%via NVD
CVE-2026-55254Medium· 4.8
3mo ago

NCalc: Denial of Service via Unbounded and Non-Terminating Factorial Evaluation

NCalc: Denial of Service via Unbounded and Non-Terminating Factorial Evaluation

▾ SunlitNCalc · NCalc.CoreEPSS 0.29%via GHSA
CVE-2026-9675High· 7.5
3mo ago

undici WebSocket client vulnerable to denial of service via cumulative fragment bypass

undici WebSocket client vulnerable to denial of service via cumulative fragment bypass

▾ Twilightundici · undiciEPSS 0.49%via GHSA
GHSA-jm82-fx9c-mx94Medium
3mo ago

pypdf: Missing stream length values ignore defined limits

pypdf: Missing stream length values ignore defined limits

▾ Sunlitpypdf · pypdfvia GHSA
GHSA-3prj-6hqw-cm82High
3mo ago

PHP JWT Library: PBES2-HS*+A*KW unwrap accepts an unbounded p2c iteration count, enabling CPU-amplification denial of service

PHP JWT Library: PBES2-HS*+A*KW unwrap accepts an unbounded p2c iteration count, enabling CPU-amplification denial of service

▾ Twilightweb-token · web-token/jwt-libraryvia GHSA
CVE-2026-48779High· 7.5PoC
3mo ago

ws is an open source WebSocket client and server for Node.js

ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7.0.0 up to 7.5.11, and from 8.0.0 up to 8.21.0 are affected by a memory exhaustion DoS v…

▾ Midnightws_project · wsEPSS 0.93%via NVD
CVE-2026-47774High· 7.5
3mo ago

Envoy is an open source edge and service proxy designed for cloud-native applications

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.35.11, 1.36.7, 1.37.3, and 1.38.1, a vulnerability in Envoy's HTTP/2 downstream request processing allows an unauthenticated remot…

▾ Twilightenvoyproxy · envoyEPSS 1.1%via NVD
CVE-2026-12151High· 7.5
3mo ago

undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames (CVE-2026-12151)

A flaw was found in undici. A malicious WebSocket server can exploit this by streaming numerous small or empty continuation frames. This can bypass per-frame and cumulative-size validation, leading to unbounded memory growth in the client …

▾ TwilightRed Hat · Red Hat Openshift Data Foundation 4.20EPSS 0.79%via CSAF
CWE-770 vulnerabilities (CVEs) — page 15 · VulnSea