VulnSea

CWE-770

CVEs classified under CWE-770, newest first.

502 CVEsRSS

CVE-2026-92078Medium· 6.5⚖ disputed
6d ago

Denial-of-service in the Security component

Denial-of-service in the Security component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

SunlitMozilla · FirefoxEPSS 0.23%via NVD
CVE-2026-92077Medium· 6.5⚖ disputed
6d ago

Denial-of-service in the SVG component

Denial-of-service in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

SunlitMozilla · FirefoxEPSS 0.29%via NVD
CVE-2026-92063Medium· 6.5⚖ disputed
6d ago

Denial-of-service in the Audio/Video component

Denial-of-service in the Audio/Video component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.

SunlitMozilla · FirefoxEPSS 0.22%via NVD
CVE-2026-92003Medium· 6.9
6d ago

Affected versions of MISP do not consistently apply the existing authentication-failure logging throttle. Two API authentication failure branches wrote directly to the Log model:  - API requests with no authentication key;  - requests…

Affected versions of MISP do not consistently apply the existing authentication-failure logging throttle. Two API authentication failure branches wrote directly to the Log model:  - API requests with no authentication key;  - requests…

SunlitMISP · MISPEPSS 0.44%via NVD
CVE-2026-53941Medium· 6.9
6d ago

Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF

Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. From 0.27.0 until 0.53.1, the uprobe library resolver can allow an unprivileged container to co…

Sunlitinspektor-gadget · inspektor-gadgetEPSS 0.38%via NVD
CVE-2026-48987Medium· 6.5PoC
6d ago

pyLoad is a free and open-source download manager written in Python

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, EventManager in src/pyload/core/managers/event_manager.py appends a Client object to the clients list for each unique uuid submitted to the aut…

Twilightpyload · pyloadEPSS 0.30%via NVD
CVE-2026-44163Medium· 5.3
6d ago

fluent-plugin-opentelemetry is a Fluentd input and output plugin for forwarding OpenTelemetry Protocol data

fluent-plugin-opentelemetry is a Fluentd input and output plugin for forwarding OpenTelemetry Protocol data. Prior to 0.5.3, the in_opentelemetry HTTP input read the entire incoming request body and decompressed payloads into memory with…

Sunlitfluent-plugins-nursery · fluent-plugin-opentelemetryEPSS 0.34%via NVD
CVE-2026-13260High· 7.5
1w ago

IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.

IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.

TwilightIBM · Verify Identity AccessEPSS 0.43%via NVD
CVE-2026-86892Medium· 5.5
1w ago

This issue was addressed with additional entitlement checks

This issue was addressed with additional entitlement checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, visionOS 27. An app may be able to cause a denial-of-service.

Sunlitapple · ipadosEPSS 0.12%via NVD
CVE-2026-91080High· 7.5PoC
1w ago

webhook through 2.8.3 reads the entire request body into memory before evaluating trigger rules, allowing unauthenticated attackers to exhaust memory by sending oversized bodies

webhook through 2.8.3 reads the entire request body into memory before evaluating trigger rules, allowing unauthenticated attackers to exhaust memory by sending oversized bodies. Attackers can send multi-gigabyte request bodies with inva…

Midnightadnanh · webhookEPSS 0.59%via NVD
CVE-2026-11993Medium· 4.3
1w ago

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to properly enforce the limit of concurrent files being processed and handled failed files, which allows a user with permission to upload …

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to properly enforce the limit of concurrent files being processed and handled failed files, which allows a user with permission to upload …

SunlitMattermost · MattermostEPSS 0.21%via NVD
CVE-2026-90713Low· 3.3PoC
1w ago

A security flaw has been discovered in vllm-project vLLM up to 0.29.0

A security flaw has been discovered in vllm-project vLLM up to 0.29.0. The affected element is the function TiktokenTokenizer::new of the file rust/src/text/src/backend/hf/mod.rs of the component tiktoken vocab File Handler. The manipula…

Twilightvllm-project · vLLMEPSS 0.15%via NVD
CVE-2026-82439Critical· 9.8
1w ago

Description The DRPC server kept a map from function name to request queue and created an entry the first time a function name was seen

Description The DRPC server kept a map from function name to request queue and created an entry the first time a function name was seen. No code path ever removed an entry: request cleanup removed the request from its queue, and the shu…

MidnightApache Software Foundation · org.apache.storm:storm-serverEPSS 0.52%via NVD
CVE-2026-54156High· 7.5
1w ago

node-opcua is an OPC UA implementation for TypeScript and Node.js

node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to 2.166.0, the process-global g_alreadyUsedNonce cache used by nonceAlreadyBeenUsed in packages/node-opcua-secure-channel/source/server/server_secure_channel_layer…

Twilightnode-opcua · node-opcuaEPSS 0.55%via NVD
CVE-2026-53752High· 7.5
1w ago

docx4j is an open source Java library for creating, editing, and saving OpenXML packages, including DOCX, PPTX, and XLSX files

docx4j is an open source Java library for creating, editing, and saving OpenXML packages, including DOCX, PPTX, and XLSX files. Prior to 11.5.14, PropertyResolver and adjacent helpers recursively follow the WordprocessingML w:basedOn sty…

Twilightplutext · docx4jEPSS 0.44%via NVD
CVE-2026-57497Medium· 5.3
1w ago

webtransport-go is an implementation of the WebTransport protocol

webtransport-go is an implementation of the WebTransport protocol. Prior to 0.11.1, Session.parseNextCapsule() in session.go skips an unknown WebTransport capsule on the HTTP/3 request stream by calling io.ReadAll on the capsule reader, …

Sunlitquic-go · webtransport-goEPSS 0.47%via NVD
CVE-2026-54247Medium· 4.3
1w ago

Skipper is an HTTP router and reverse proxy for service composition

Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.26.22, Handler in dataclients/kubernetes/admission/admission.go passes the body of requests to the Kubernetes admission endpoint at :9443/admission directly …

Sunlitzalando · skipperEPSS 0.23%via NVD
CVE-2026-50270High· 7.5
1w ago

dd-trace-java is a Datadog APM client for Java

dd-trace-java is a Datadog APM client for Java. Prior to 1.62.0, W3C baggage extraction does not enforce DD_TRACE_BAGGAGE_MAX_ITEMS, which defaults to 64, or DD_TRACE_BAGGAGE_MAX_BYTES, which defaults to 8192, although those limits apply…

TwilightDataDog · dd-trace-javaEPSS 0.56%via NVD
CVE-2026-50276High· 7.5
1w ago

dd-trace-rb is Datadog's client library for Ruby

dd-trace-rb is Datadog's client library for Ruby. Prior to 2.32.0, W3C baggage extraction does not enforce DD_TRACE_BAGGAGE_MAX_ITEMS, which defaults to 64, or DD_TRACE_BAGGAGE_MAX_BYTES, which defaults to 8192, although those limits app…

TwilightDataDog · dd-trace-rbEPSS 0.76%via NVD
CVE-2026-44162Low· 2.7
1w ago

fluent-plugin-s3 is an Amazon S3 input and output plugin for Fluentd

fluent-plugin-s3 is an Amazon S3 input and output plugin for Fluentd. From 0.7.0 to 1.8.4, the in_s3 input plugin reads the entire decompressed payload of gzip, lzma2, and lzop objects into memory without enforcing a decompression_size_l…

Sunlitfluent · fluent-plugin-s3EPSS 0.35%via NVD
CVE-2026-90668High· 7.5
1w ago

The webserver in UnrealIRCd 6.0.5 through 6.2.6 before 6.2.7 does not limit the number of HTTP request headers, which allows remote attackers to cause a denial of service (memory consumption and unresponsive server) via an HTTP request w…

The webserver in UnrealIRCd 6.0.5 through 6.2.6 before 6.2.7 does not limit the number of HTTP request headers, which allows remote attackers to cause a denial of service (memory consumption and unresponsive server) via an HTTP request w…

TwilightUnrealIRCd · UnrealIRCdEPSS 0.33%via NVD
CVE-2026-90584Medium· 5.3PoC
1w ago

A weakness has been identified in TooTallNate Java-WebSocket up to 1.6.1

A weakness has been identified in TooTallNate Java-WebSocket up to 1.6.1. The impacted element is the function processFrameContinuousAndNonFin of the file Draft_6455.java of the component Fragmentation Handler. Executing a manipulation c…

TwilightTooTallNate · Java-WebSocketEPSS 0.42%via NVD
CVE-2026-89604Medium· 5.5
1w ago

kernel: efivarfs: Rate limit statfs() handler (CVE-2026-89604)

A flaw was found in the Linux kernel's efivarfs component. An unprivileged local user can exploit this by repeatedly calling the `statfs()` handler on the `efivarfs` mount point. This action triggers a flood of calls to the `QueryVariableI…

SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.21%via CSAF
CVE-2026-89699Medium· 5.5⚖ disputed
1w ago

kernel: nfsd: validate symlink target length in NFSv4 CREATE (CVE-2026-89699)

A flaw was found in the Linux kernel's Network File System Daemon (nfsd) when handling NFSv4 CREATE operations. A remote attacker can exploit this by sending a crafted request with an oversized symbolic link (symlink) target length. This u…

SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.51%via CSAF
CVE-2026-54135High· 7.5PoC
1w ago

AirSane is a SANE frontend, and a scanner server that supports Apple's AirScan protocol

AirSane is a SANE frontend, and a scanner server that supports Apple's AirScan protocol. Versions prior to 0.4.12 have a vulnerability in the custom HTTP server implementation of AirSane that allows a remote unauthenticated attacker to c…

MidnightSimulPiscator · AirSaneEPSS 0.55%via NVD
CVE-2026-81009Medium· 5.5
1w ago

In the Linux kernel, the following vulnerability has been resolved: io_uring/query: cap user size passed to copy_struct_to_user io_handle_query_entry() clamps hdr.size for the inbound copy_from_user() but keeps the original user value …

In the Linux kernel, the following vulnerability has been resolved: io_uring/query: cap user size passed to copy_struct_to_user io_handle_query_entry() clamps hdr.size for the inbound copy_from_user() but keeps the original user value …

SunlitLinux · LinuxEPSS 0.17%via NVD
CVE-2026-80996Medium· 5.5
1w ago

kernel: net: l2tp: do not propagate multicast notification errors (CVE-2026-80996)

A flaw was found in the Linux kernel's L2TP (Layer 2 Tunneling Protocol) networking component. Specifically, the netlink handlers responsible for creating and modifying L2TP tunnels and sessions may fail to propagate multicast notification…

SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.17%via CSAF
CVE-2026-87908High· 7.5
1w ago

multiparty is a Node.js library for parsing multipart/form-data request bodies

multiparty is a Node.js library for parsing multipart/form-data request bodies. In versions from 2.1.0 up to but not including 4.3.1, the parser does not bound the amount of memory used while accumulating the headers of a single multipar…

Twilightmultiparty · multipartyEPSS 0.30%via NVD
CVE-2026-50018Medium· 6.5PoC
1w ago

Hoverfly is an open source API simulation tool

Hoverfly is an open source API simulation tool. Prior to version 1.12.8, remote post-serve actions use `http.DefaultClient` without any timeout configuration. When the remote endpoint is unreachable or intentionally slow (accepts TCP con…

TwilightSpectoLabs · hoverflyEPSS 0.30%via NVD
CVE-2026-48496Medium· 6.2
1w ago

OpenTelemetry eBPF Profiler is a production-scale agent for profiling applications across multiple programming languages

OpenTelemetry eBPF Profiler is a production-scale agent for profiling applications across multiple programming languages. Starting in version 0.0.202527 and prior to version 0.0.202622, an unprivileged process can cause the profiler to o…

Sunlitopen-telemetry · opentelemetry-ebpf-profilerEPSS 0.14%via NVD
CWE-770 vulnerabilities (CVEs) — page 3 · VulnSea