VulnSea

CWE-770

CVEs classified under CWE-770, newest first.

588 CVEsRSS

CVE-2026-48735Medium
3mo ago

pypdf: Manipulated XMP metadata streams can exhaust RAM

pypdf: Manipulated XMP metadata streams can exhaust RAM

▾ Sunlitpypdf · pypdfEPSS 0.18%via GHSA
CVE-2026-48853Critical· 9.2PoC
3mo ago

Deserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities in elixir-grpc grpc allow unauthenticated attackers to crash the BEAM node via atom table exhaustion and, when a decoded term flow…

Deserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities in elixir-grpc grpc allow unauthenticated attackers to crash the BEAM node via atom table exhaustion and, when a decoded term flow…

▾ Abyssalelixir-grpc · grpcEPSS 0.78%via NVD
CVE-2026-48854High· 8.7PoC
3mo ago

Allocation of Resources Without Limits or Throttling vulnerability in elixir-grpc grpc allows unauthenticated attackers to exhaust the BEAM's memory and crash the server by streaming a large or slow-trickle unary request body. 'Elixir.G…

Allocation of Resources Without Limits or Throttling vulnerability in elixir-grpc grpc allows unauthenticated attackers to exhaust the BEAM's memory and crash the server by streaming a large or slow-trickle unary request body. 'Elixir.G…

▾ Midnightelixir-grpc · grpcEPSS 0.45%via NVD
CVE-2026-54277Medium
3mo ago

aiohttp: C HTTP Parser Bypasses max_line_size for Fragmented Lines

aiohttp: C HTTP Parser Bypasses max_line_size for Fragmented Lines

▾ Sunlitaiohttp · aiohttpEPSS 0.56%via OSV
CVE-2026-54273Medium
3mo ago

aiohttp: HTTP/1 Pipelined Requests Queue Without Limit

aiohttp: HTTP/1 Pipelined Requests Queue Without Limit

▾ Sunlitaiohttp · aiohttpEPSS 0.49%via OSV
CVE-2026-54274Medium
3mo ago

aiohttp: Incomplete websocket frame payloads bypass memory limits

aiohttp: Incomplete websocket frame payloads bypass memory limits

▾ Sunlitaiohttp · aiohttpEPSS 0.54%via OSV
CVE-2026-54270Medium· 5.3
3mo ago

protobufjs: Memory amplification from preserved unknown fields in binary decode

protobufjs: Memory amplification from preserved unknown fields in binary decode

▾ Sunlitprotobufjs · protobufjsEPSS 0.40%via GHSA
CVE-2026-54285Medium· 5.3
3mo ago

OpenTelemetry Core: Unbounded memory allocation in W3C Baggage propagation

OpenTelemetry Core: Unbounded memory allocation in W3C Baggage propagation

▾ Sunlitopentelemetry · @opentelemetry/coreEPSS 0.40%via GHSA
CVE-2026-48748High· 7.5
3mo ago

Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion

Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion

▾ Twilightnetty · io.netty:netty-codec-http3EPSS 0.68%via GHSA
CVE-2026-46340High· 7.5
3mo ago

Netty is a network application framework for development of protocol servers and clients

Netty is a network application framework for development of protocol servers and clients. In versions of netty-transport-sctp prior to 4.1.135.Final and 4.2.15.Final, for each non-complete SctpMessage fragment the handler does `fragments…

▾ Twilightnetty · nettyEPSS 0.85%via NVD
CVE-2026-47244Medium· 5.3
3mo ago

netty-codec-http2: Netty: Denial of Service via uncontrolled HTTP/2 concurrent streams (CVE-2026-47244)

A flaw was found in Netty, a network application framework. A remote attacker can exploit this vulnerability by sending a large number of HTTP/2 stream requests to a Netty HTTP/2 server. If the server does not explicitly limit concurrent s…

▾ SunlitRed Hat · OpenShift ServerlessEPSS 0.51%via CSAF
CVE-2026-28980High
3mo ago

SwiftNIO NIOHTTP1: HTTPDecoder accepts unbounded HTTP/1 header blocks, enabling remote DoS

SwiftNIO NIOHTTP1: HTTPDecoder accepts unbounded HTTP/1 header blocks, enabling remote DoS

▾ Twilightapple · github.com/apple/swift-niovia GHSA
CVE-2026-28975Medium
3mo ago

NIOExtras: NIOHTTPRequestDecompressor ratio limit bypass via inflated Content-Length

NIOExtras: NIOHTTPRequestDecompressor ratio limit bypass via inflated Content-Length

▾ Sunlitapple · github.com/apple/swift-nio-extrasvia GHSA
CVE-2026-50011High· 7.5PoC
3mo ago

Netty is a network application framework for development of protocol servers and clients

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, RedisArrayAggregator pre-allocates ArrayList with initial capacity equal to the RESP array elemen…

▾ Midnightnetty · nettyEPSS 0.85%via NVD
CVE-2026-50560Medium· 5.3
3mo ago

netty-codec-http2: Netty: Denial of Service due to HTTP/2 max header size handling (CVE-2026-50560)

A flaw was found in Netty, a network application framework. A remote attacker can exploit a vulnerability in the HTTP/2 (Hypertext Transfer Protocol version 2) maximum header size handling. By sending a specific SETTINGS_MAX_HEADER_LIST_SI…

▾ SunlitRed Hat · OpenShift ServerlessEPSS 0.52%via CSAF
CVE-2026-45416High· 7.5
3mo ago

Netty is a network application framework for development of protocol servers and clients

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SslClientHelloHandler.decode() reads the 24-bit TLS handshake length and, when the ClientHello do…

▾ Twilightnetty · nettyEPSS 1.6%via NVD
CVE-2026-44488High· 7.5PoC
3mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.x did not enforce configured request and response size limits when requests were sent with the fetch adapter. Applications that selected …

▾ Midnightaxios · axiosEPSS 0.93%via NVD
CVE-2026-44250High· 7.5
3mo ago

Netty is a network application framework for development of protocol servers and clients

Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can cause DoS by sending a crafted Redis payload with deeply nes…

▾ Twilightnetty · nettyEPSS 0.85%via NVD
CVE-2026-44890High· 7.5
3mo ago

Netty is a network application framework for development of protocol servers and clients

Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can cause DoS by sending crafted Redis payloads across multiple …

▾ Twilightnetty · nettyEPSS 0.85%via NVD
CVE-2026-48045Medium· 6.5
3mo ago

python-zeroconf: Unbounded TC-deferred queue allows LAN-local memory exhaustion via spoofed-source flood

python-zeroconf: Unbounded TC-deferred queue allows LAN-local memory exhaustion via spoofed-source flood

▾ Sunlitzeroconf · zeroconfEPSS 0.37%via GHSA
CVE-2026-5497High· 7.5
3mo ago

vLLM versions 0.8.0 and later are vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded frame count processing in the `VideoMediaIO.load_base64()` method

vLLM versions 0.8.0 and later are vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded frame count processing in the `VideoMediaIO.load_base64()` method. When processing `video/jpeg` data URLs, the method …

▾ Twilightvllm · vllmEPSS 0.90%via NVD
CVE-2026-41716High· 7.5
3mo ago

Spring Data's internal property-lookup cache accepts and permanently retains attacker-supplied strings as cache keys, allowing heap exhaustion through repeated requests. Affected versions: Spring Data Commons 2.7.0 through 2.7.19; 3.3.0…

Spring Data's internal property-lookup cache accepts and permanently retains attacker-supplied strings as cache keys, allowing heap exhaustion through repeated requests. Affected versions: Spring Data Commons 2.7.0 through 2.7.19; 3.3.0…

▾ Twilightbroadcom · spring_data_commonsEPSS 0.46%via NVD
CVE-2026-41726Medium· 6.5
3mo ago

In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector header

In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector header

▾ Sunlitspringframework · org.springframework.kafka:spring-kafkaEPSS 0.42%via GHSA
CVE-2026-41710Medium· 5.9PoC
3mo ago

An attacker can craft a large number of unique requests that trigger a failure, exhausting the capacity of the application-wide stateful retry cache

An attacker can craft a large number of unique requests that trigger a failure, exhausting the capacity of the application-wide stateful retry cache. Once the cache is full, it permanently rejects any further updates, causing all later s…

▾ Twilightbroadcom · spring_retryEPSS 0.37%via NVD
CVE-2026-41851Medium· 5.3
3mo ago

Applications which accept user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack if the evaluation of a SpEL expression triggers unbounded cache growth. Affected versions: Sprin…

Applications which accept user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack if the evaluation of a SpEL expression triggers unbounded cache growth. Affected versions: Sprin…

▾ Sunlitvmware · spring_frameworkEPSS 0.46%via NVD
CVE-2026-41007High· 7.5
3mo ago

Spring HATEOAS maintains an unbounded static cache of StringLinkRelation instances keyed on attacker-supplied strings. Affected versions: Spring HATEOAS 1.5.0 through 1.5.6; 2.3.0 through 2.3.4; 2.4.0 through 2.4.1; 2.5.0 through 2.5.2;…

Spring HATEOAS maintains an unbounded static cache of StringLinkRelation instances keyed on attacker-supplied strings. Affected versions: Spring HATEOAS 1.5.0 through 1.5.6; 2.3.0 through 2.3.4; 2.4.0 through 2.4.1; 2.5.0 through 2.5.2;…

▾ Twilightvmware · spring_hateoasEPSS 0.46%via NVD
CVE-2026-40984High· 7.5
3mo ago

In Micrometer, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Affected versions: micrometer-core 1.16.0 through 1.16.5; 1.15.0 through 1.15.11; 1.14.0 through 1.1…

In Micrometer, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Affected versions: micrometer-core 1.16.0 through 1.16.5; 1.15.0 through 1.15.11; 1.14.0 through 1.1…

▾ TwilightSpring · micrometer-coreEPSS 1.1%via NVD
CVE-2026-8469High
3mo ago

PhoenixStorybook: Unbounded atom creation from LiveView event params (atom-table DoS)

PhoenixStorybook: Unbounded atom creation from LiveView event params (atom-table DoS)

▾ Twilightphoenix_storybook · phoenix_storybookEPSS 0.52%via GHSA
CVE-2026-40983High· 7.5
3mo ago

In Micrometer, it is possible for a user to provide specially crafted gRPC requests that may cause a denial-of-service (DoS) condition. Affected versions: Micrometer 1.16.0 through 1.16.5; 1.15.0 through 1.15.11.

In Micrometer, it is possible for a user to provide specially crafted gRPC requests that may cause a denial-of-service (DoS) condition. Affected versions: Micrometer 1.16.0 through 1.16.5; 1.15.0 through 1.15.11.

▾ TwilightSpring · MicrometerEPSS 0.85%via NVD
CVE-2026-45409Medium· 5.3
3mo ago

python-idna: idna: Denial of Service via specially crafted long inputs (CVE-2026-45409)

A flaw was found in the idna library, which handles Internationalized Domain Names in Python applications. A remote attacker could exploit this vulnerability by sending specially crafted, excessively long inputs to the library's encoding f…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.46%via CSAF
CWE-770 vulnerabilities (CVEs) — page 16 · VulnSea