VulnSea

CWE-770

CVEs classified under CWE-770, newest first.

588 CVEsRSS

CVE-2026-82728None
3w ago

Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint allows a remote HTTP server to exhaust memory on the client host and cause a denial of service. Two HTTP/1 response-parser states accumulate server d…

Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint allows a remote HTTP server to exhaust memory on the client host and cause a denial of service. Two HTTP/1 response-parser states accumulate server d…

▾ SunlitEPSS 0.52%via NVD
CVE-2026-85584High· 7.5PoC
3w ago

SiYuan versions before v3.8.2 contain a denial of service vulnerability in the publish-service Basic Auth throttle that stores failed-attempt state using attacker-controlled usernames without enforcing capacity limits or eviction policie…

SiYuan versions before v3.8.2 contain a denial of service vulnerability in the publish-service Basic Auth throttle that stores failed-attempt state using attacker-controlled usernames without enforcing capacity limits or eviction policie…

▾ Midnightsiyuan-note · siyuanEPSS 0.59%via NVD
CVE-2026-82309Medium· 4.3
3w ago

Robots::Validate versions from 0.3.2 before 0.3.11 for Perl allow unbounded outbound DNS queries per validation via a forward-confirmation loop that does not bound the names it queries. _check_dns issues one PTR query for the client add…

Robots::Validate versions from 0.3.2 before 0.3.11 for Perl allow unbounded outbound DNS queries per validation via a forward-confirmation loop that does not bound the names it queries. _check_dns issues one PTR query for the client add…

▾ SunlitEPSS 0.37%via NVD
CVE-2026-71224Medium· 4.7
3w ago

A stack overflow vulnerability was found in gfs2-utils

A stack overflow vulnerability was found in gfs2-utils. The metadata walk code in metawalk.c uses alloca() with an untrusted inode height value from on-disk metadata without bounds validation, causing stack exhaustion and a denial of ser…

▾ Sunlitredhat · enterprise_linuxEPSS 0.14%via NVD
CVE-2026-71219Medium· 4.7
3w ago

A stack overflow vulnerability was found in gfs2-utils

A stack overflow vulnerability was found in gfs2-utils. The hash table traversal code in metawalk.c uses alloca() with an exponentially-derived size from the untrusted on-disk di_depth field without bounds validation. A crafted GFS2 file…

▾ Sunlitredhat · enterprise_linuxEPSS 0.14%via NVD
CVE-2026-85450High· 7.5
3w ago

MOOS core-moos through 10.4.0 contains a denial of service vulnerability in the MOOSDB HTTP server that creates unbounded connections and threads without limits

MOOS core-moos through 10.4.0 contains a denial of service vulnerability in the MOOSDB HTTP server that creates unbounded connections and threads without limits. Attackers can open many connections and send endless header data to exhaust…

▾ TwilightEPSS 0.63%via NVD
CVE-2026-85448High· 7.5
3w ago

MOOS-IvP uFldShoreBroker through 24.8.1 fails to limit the number of claimed communities stored in parallel vectors within ShoreBroker::handleMailNodePing()

MOOS-IvP uFldShoreBroker through 24.8.1 fails to limit the number of claimed communities stored in parallel vectors within ShoreBroker::handleMailNodePing(). A single publisher can supply unbounded distinct community names to grow retain…

▾ Twilightmoos-ivp · moos-ivpEPSS 0.63%via NVD
CVE-2026-85447High· 7.5
3w ago

MOOS-IvP pRealm through version 24.8.1 accepts unbounded REALMCAST_REQ subscriptions without validating duration or variable list limits

MOOS-IvP pRealm through version 24.8.1 accepts unbounded REALMCAST_REQ subscriptions without validating duration or variable list limits. Attackers can register long-lived pipeways with many variables to cause pRealm to generate excessiv…

▾ TwilightEPSS 0.63%via NVD
CVE-2026-85449High· 7.5
3w ago

MOOS-IvP pMarineViewer through 24.8.1 fails to limit the number of tracked node identities from NODE_REPORT messages, allowing attackers to exhaust memory by supplying unbounded distinct node names

MOOS-IvP pMarineViewer through 24.8.1 fails to limit the number of tracked node identities from NODE_REPORT messages, allowing attackers to exhaust memory by supplying unbounded distinct node names. Attackers can publish crafted NODE_REP…

▾ Twilightmoos-ivp · moos-ivpEPSS 0.74%via NVD
CVE-2026-84778High· 7.5
3w ago

Unauthenticated Denial of Service Attack in Migrate Guru – Site Migration &amp; Cloning <= 6.65 versions.

Unauthenticated Denial of Service Attack in Migrate Guru – Site Migration &amp; Cloning <= 6.65 versions.

▾ TwilightEPSS 0.46%via NVD
CVE-2026-49249High· 7.1PoC
3w ago

Boruta is a standalone authorization server that aims to implement OAuth 2.0 and Openid Connect up to decentralized identity specifications

Boruta is a standalone authorization server that aims to implement OAuth 2.0 and Openid Connect up to decentralized identity specifications. Prior to version 0.10.0, BorutaIdentityWeb.UserSettingsController.update/2 atomizes every key of…

▾ Midnightmalach-it · boruta-serverEPSS 0.40%via NVD
CVE-2026-77121None
3w ago

A user account with permission to deploy artifacts to a hosted Maven repository could upload a POM file containing an oversized metadata field

A user account with permission to deploy artifacts to a hosted Maven repository could upload a POM file containing an oversized metadata field. This causes future attempts to list or browse that repository's components to permanently fai…

▾ SunlitEPSS 0.40%via NVD
CVE-2026-83615High· 7.5
3w ago

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom versions 0.1.5 through 0.6.0, appendElement in lib/sax.js uses _c…

▾ Twilightxmldom · @xmldom/xmldomEPSS 0.59%via NVD
CVE-2026-74835High· 8.7
3w ago

The inets application HTTP server httpd fails to enforce a configured body-size limit on chunked request. This issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6,…

The inets application HTTP server httpd fails to enforce a configured body-size limit on chunked request. This issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6,…

▾ TwilightErlang · otpEPSS 0.58%via NVD
CVE-2026-70399High· 8.7
3w ago

Allocation of Resources Without Limits or Throttling vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by opening and holding open a large number of connections

Allocation of Resources Without Limits or Throttling vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by opening and holding open a large number of connections. The max_clients …

▾ TwilightErlang · otpEPSS 0.93%via NVD
CVE-2026-55951High· 8.2
3w ago

The Erlang/OTP httpc HTTP client does not enforce a limit on the total size of response headers received from a server

The Erlang/OTP httpc HTTP client does not enforce a limit on the total size of response headers received from a server. The max_header_size option defaults to nolimit, and httpc_response:parse_headers/6 accumulates every header into a li…

▾ TwilightErlang · otpEPSS 0.69%via NVD
CVE-2026-84311Medium· 5.5
3w ago

pypdf is a free and open-source pure-python PDF library

pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_page.py PageObject._extract_text and PageObject.extract_xform_text to traverse a directed acyclic graph of reused fo…

▾ Sunlitpypdf · pypdfEPSS 0.18%via NVD
CVE-2026-84310Medium· 5.5
3w ago

pypdf is a free and open-source pure-python PDF library

pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_doc_common.py _get_outline to consume long runtimes and large amounts of memory when retrieving document outlines wi…

▾ Sunlitpypdf · pypdfEPSS 0.18%via NVD
GHSA-8423-8fgw-73vqMedium
3w ago

tornado: multipart split() creates huge temp list before max_parts check -> memory amplification DoS (httputil.py:34)

tornado: multipart split() creates huge temp list before max_parts check -> memory amplification DoS (httputil.py:34)

▾ Sunlittornado · tornadovia OSV
CVE-2026-81624High· 7.5
3w ago

Undertow is a flexible performant web server used in JBoss EAP and WildFly

Undertow is a flexible performant web server used in JBoss EAP and WildFly. A flaw was found in how Undertow handles WebSocket connections. Specifically, certain configuration limits like message buffer sizes and session timeouts cannot …

▾ TwilightRed Hat · undertow-coreEPSS 0.58%via NVD
CVE-2026-81636None
4w ago

Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_graphql allows an unauthenticated client to bypass the configured GraphQL query-complexity limit and force an unbounded database read. AshGraphql.Grap…

Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_graphql allows an unauthenticated client to bypass the configured GraphQL query-complexity limit and force an unbounded database read. AshGraphql.Grap…

▾ SunlitEPSS 0.55%via NVD
CVE-2026-82562Low· 3.7
4w ago

### Summary When `qs.parse` is called with `comma: true` and `throwOnLimitExceeded: true`, a comma-separated value under a bracket-push key (`a[]=1,2,3,4`) is split into an array without being compared against `arrayLimit`, while the …

### Summary When `qs.parse` is called with `comma: true` and `throwOnLimitExceeded: true`, a comma-separated value under a bracket-push key (`a[]=1,2,3,4`) is split into an array without being compared against `arrayLimit`, while the …

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.54%via NVD
CVE-2026-37736High· 7.5
1mo ago

An issue in the JsonSanitizer.sanitize() component of OWASP json-sanitizer v1.2.3 allows attackers to cause a Denial of Service (DoS) via a crafted input.

An issue in the JsonSanitizer.sanitize() component of OWASP json-sanitizer v1.2.3 allows attackers to cause a Denial of Service (DoS) via a crafted input.

▾ TwilightEPSS 0.49%via NVD
CVE-2026-37237High· 7.5
1mo ago

vLLM up to and including 0.17.0 allows remote attackers to cause a Denial of Service via memory exhaustion

vLLM up to and including 0.17.0 allows remote attackers to cause a Denial of Service via memory exhaustion. The AsyncMediaIO.fetch_audio and AsyncMediaIO.fetch_image functions in multimodal/inputs.py fetch user-supplied media URLs using …

▾ TwilightRed Hat · Red Hat AI Inference ServerEPSS 0.75%via NVD
CVE-2026-55407Medium
1mo ago

Buffa Vulnerable to Memory Exhaustion Denial of Service in decode_unknown_field via Unbounded Allocation

Buffa Vulnerable to Memory Exhaustion Denial of Service in decode_unknown_field via Unbounded Allocation

▾ Sunlitbuffa · buffaEPSS 0.76%via GHSA
CVE-2026-54788High· 7.5
1mo ago

dd-trace-rs provides Datadog application performance monitoring for Rust

dd-trace-rs provides Datadog application performance monitoring for Rust. From 0.1.0 until 0.3.3, datadog-opentelemetry/src/propagation/tracecontext.rs parses the W3C tracestate header and collects every semicolon-separated key and value…

▾ Twilightdatadog-opentelemetry · datadog-opentelemetryEPSS 0.79%via NVD
CVE-2026-47885High· 7.5
1mo ago

The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSize limit when maxInMemorySize is set to -1. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28

The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSize limit when maxInMemorySize is set to -1. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28

▾ Twilightvmware · spring_frameworkEPSS 0.37%via NVD
CVE-2026-81699High· 7.5
1mo ago

openssl_encrypt versions before 1.4.9 fail to properly validate key derivation function costs in crafted files, allowing attackers to trigger unbounded memory and CPU exhaustion during pre-authentication processing

openssl_encrypt versions before 1.4.9 fail to properly validate key derivation function costs in crafted files, allowing attackers to trigger unbounded memory and CPU exhaustion during pre-authentication processing. Attackers can supply …

▾ Twilightjahlives · openssl_encryptEPSS 0.51%via NVD
CVE-2026-47886High· 7.5
1mo ago

Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack when the power operator (^) is used with a BigDecimal or BigInteger operand and a large exponent…

Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack when the power operator (^) is used with a BigDecimal or BigInteger operand and a large exponent…

▾ Twilightvmware · spring_frameworkEPSS 0.46%via NVD
CVE-2026-80179Medium· 5.9PoC
1mo ago

Jwcrypto: jwcrypto: denial of service via malformed jwe tokens

A flaw was found in jwcrypto. A remote attacker can send a specially crafted JSON Web Encryption (JWE) token containing numerous period delimiters. This malformed token can force the JWE.deserialize() function to allocate excessive memor…

▾ TwilightRed Hat · ansible-automation-platform-24/controller-rhel8EPSS 0.41%via CVEORG
CWE-770 vulnerabilities (CVEs) — page 7 · VulnSea