VulnSea

CWE-770

CVEs classified under CWE-770, newest first.

588 CVEsRSS

CVE-2026-41178High· 7.5
3mo ago

github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denia…

A flaw was found in OpenTelemetry-Go. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by sending oversized or invalid baggage headers. The `Parse` function, in affected versions, failed to reject raw-length i…

▾ TwilightRed Hat · Red Hat Openshift Data Foundation 4.22EPSS 0.34%via CSAF
CVE-2026-48597Medium· 5.9PoC⚖ disputed
3mo ago

Allocation of Resources Without Limits or Throttling vulnerability in elixir-tesla tesla allows denial of service via atom table exhaustion in Tesla.Adapter.Mint. Tesla.Adapter.Mint.open_conn/2 converts the URL scheme of every outgoing …

Allocation of Resources Without Limits or Throttling vulnerability in elixir-tesla tesla allows denial of service via atom table exhaustion in Tesla.Adapter.Mint. Tesla.Adapter.Mint.open_conn/2 converts the URL scheme of every outgoing …

▾ Twilightelixir-tesla · teslaEPSS 0.63%via NVD
CVE-2026-45292Medium· 5.3⚖ disputed
4mo ago

opentelemetry-java is the Java implementation of the OpenTelemetry API for recording telemetry, and SDK for managing telemetry recorded by the API

opentelemetry-java is the Java implementation of the OpenTelemetry API for recording telemetry, and SDK for managing telemetry recorded by the API. Prior to 1.62.0, a vulnerability affects the baggage propagation implementation in opente…

▾ Sunlitopen-telemetry · opentelemetry-javaEPSS 0.85%via NVD
CVE-2026-3039High· 7.5
4mo ago

BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory consumption when receiving and processing maliciously-constructed packets

BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory consumption when receiving and processing maliciously-constructed packets. Typically these servers will be found in …

▾ Twilightisc · bindEPSS 2.3%via NVD
CVE-2026-8488Medium· 4.3
4mo ago

Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation allows Excessive Allocation. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.

Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation allows Excessive Allocation. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.

▾ Sunlitprogress · moveit_automationEPSS 0.45%via NVD
CVE-2026-8486Medium· 5.3
4mo ago

Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation allows Flooding. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.

Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation allows Flooding. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.

▾ Sunlitprogress · moveit_automationEPSS 0.49%via NVD
CVE-2026-41292High· 7.5
4mo ago

NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to a degradation of service attack related to parsing long lists of incoming EDNS options

NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to a degradation of service attack related to parsing long lists of incoming EDNS options. An adversary sending queries with too many EDNS options can hold Unbound threa…

▾ Twilightnlnetlabs · unboundEPSS 0.83%via NVD
CVE-2026-44216High· 7.5
4mo ago

Wasmtime is a runtime for WebAssembly

Wasmtime is a runtime for WebAssembly. From 30.0.0 to 36.0.8, 43.0.2, and 44.0.1, Wasmtime's allocation logic for a WebAssembly table contained checked arithmetic which panicked on overflow. This overflow is possible to trigger, and thus…

▾ Twilightbytecodealliance · wasmtimeEPSS 0.58%via NVD
CVE-2026-44004High· 7.5
4mo ago

vm2 is an open source vm/sandbox for Node.js

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, sandboxed code can call Buffer.alloc() with an arbitrary size to allocate memory directly on the host heap. Because Buffer.alloc is a synchronous C++ native call, vm2's timeo…

▾ Twilightvm2_project · vm2EPSS 0.66%via NVD
CVE-2026-44248Medium· 5.3⚖ disputed
4mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any message size limit is applied. Specifically, in MqttDec…

▾ Sunlitnetty · nettyEPSS 0.72%via NVD
CVE-2026-42582High· 7.5
4mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute new byt…

▾ Twilightnetty · nettyEPSS 0.49%via NVD
CVE-2026-44579High· 7.5PoC
4mo ago

Next.js is a React framework for building full-stack web applications

Next.js is a React framework for building full-stack web applications. From to before 15.5.16 and 16.2.5, applications using Partial Prerendering through the Cache Components feature can be vulnerable to connection exhaustion through cr…

▾ Midnightvercel · next.jsEPSS 0.76%via NVD
CVE-2026-44577Medium· 5.9
4mo ago

Next.js is a React framework for building full-stack web applications

Next.js is a React framework for building full-stack web applications. From 10.0.0 to before 15.5.16 and 16.2.5, when self-hosting Next.js with the default image loader, the Image Optimization API fetches local images entirely into memor…

▾ Sunlitvercel · next.jsEPSS 0.94%via NVD
CVE-2026-42587High· 7.5PoC
4mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb at…

▾ Midnightnetty · nettyEPSS 1.0%via NVD
CVE-2026-40629High· 7.5
4mo ago

When SSL profiles are configured on a virtual server, undisclosed traffic can cause the virtual server to stop processing new client connections.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

When SSL profiles are configured on a virtual server, undisclosed traffic can cause the virtual server to stop processing new client connections.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

▾ TwilightEPSS 0.46%via NVD
CVE-2026-40423High· 7.5
4mo ago

When a SIP profile is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

When a SIP profile is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

▾ TwilightEPSS 0.46%via NVD
CVE-2026-41227High· 7.5
4mo ago

On an HTTP/2 virtual server with Layer 7 DoS Protection configured, undisclosed traffic can result in an increase in memory consumption causing the Traffic Management Microkernel (TMM) process to terminate.  Note: Software versions which…

On an HTTP/2 virtual server with Layer 7 DoS Protection configured, undisclosed traffic can result in an increase in memory consumption causing the Traffic Management Microkernel (TMM) process to terminate.  Note: Software versions which…

▾ TwilightEPSS 0.46%via NVD
CVE-2026-42006Medium· 4.3
4mo ago

An attacker can cause uncontrolled memory usage with excessive bracing over IMAP

An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomplete, only blocking one way of doing this, so there was still another way left open. In particular, the fix was for clo…

▾ Sunlitdovecot · dovecotEPSS 0.82%via NVD
CVE-2026-22925High· 7.5
4mo ago

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0)

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application is susceptible to resource exhaustion when subjected to high volume of TCP SYN packets This could allow an attacker to render the ser…

▾ TwilightEPSS 0.32%via NVD
CVE-2026-43329High· 7.8
4mo ago

In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: strictly check for maximum number of actions The maximum number of flowtable hardware offload actions in IPv6 is: * ethernet mangling (4 payload…

In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: strictly check for maximum number of actions The maximum number of flowtable hardware offload actions in IPv6 is: * ethernet mangling (4 payload…

▾ Twilightlinux · linux_kernelEPSS 0.19%via NVD
CVE-2026-39820High· 7.5
4mo ago

Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.

Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.

▾ Twilightgolang · goEPSS 0.87%via NVD
CVE-2026-23870High· 7.5PoC
4mo ago

A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to server crashes, out-of-memory exceptions or excessive CPU usage; affecting the following pac…

A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to server crashes, out-of-memory exceptions or excessive CPU usage; affecting the following pac…

▾ Midnightfacebook · react-server-dom-parcelEPSS 1.5%via NVD
CVE-2026-42154High· 7.5PoC
4mo ago

Prometheus is an open-source monitoring system and time series database

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a snappy-compressed request body before…

▾ Midnightprometheus · prometheusEPSS 0.89%via NVD
CVE-2026-42198High· 7.5
5mo ago

pgjdbc is an open source postgresql JDBC Driver

pgjdbc is an open source postgresql JDBC Driver. From version 42.2.0 to before version 42.7.11, pgjdbc is vulnerable to a client-side denial of service during SCRAM-SHA-256 authentication. A malicious server can instruct the driver to pe…

▾ Twilightpostgresql · postgresql_jdbc_driverEPSS 4.1%via NVD
CVE-2026-42039High· 7.5PoC
5mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, toFormData recursively walks nested objects with no depth limit, so a deeply nested value passed as request data crashes the Node.js process wi…

▾ Midnightaxios · axiosEPSS 0.97%via NVD
CVE-2026-21728High· 7.5
5mo ago

Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy. Mitigation can be done by setting max_result_limit in the search config, e.g

Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy. Mitigation can be done by setting max_result_limit in the search config, e.g. to …

▾ Twilightgrafana · tempoEPSS 0.64%via NVD
CVE-2026-35469Medium· 6.5⚖ disputed
5mo ago

spdystream is a Go library for multiplexing streams over SPDY connections

spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame parser does not validate attacker-controlled counts and lengths before allocating memory. Three allocation paths are…

▾ Sunlitmoby · spdystreamEPSS 0.79%via NVD
CVE-2026-3505High· 7.5
5mo ago

Allocation of resources without limits or throttling, Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc

Allocation of resources without limits or throttling, Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpg on all (pg modules). This vulnerability is associated with program files AEADEncData…

▾ TwilightLegion of the Bouncy Castle Inc. · bcpgEPSS 0.88%via NVD
CVE-2026-40192High· 7.5
5mo ago

Pillow is a Python imaging library

Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file coul…

▾ Twilightpython · pillowEPSS 0.87%via NVD
CVE-2026-23869High· 7.5PoC
5mo ago

A denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack and react-server-dom-webpack (versions 19.0.0 through 19.0.4, 19.1.0 through 19.1.…

A denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack and react-server-dom-webpack (versions 19.0.0 through 19.0.4, 19.1.0 through 19.1.…

▾ MidnightEPSS 1.6%via NVD
CWE-770 vulnerabilities (CVEs) — page 17 · VulnSea