VulnSea

CWE-770

CVEs classified under CWE-770, newest first.

588 CVEsRSS

CVE-2026-73541High· 8.2
1mo ago

Allocation of Resources Without Limits or Throttling in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet through concurrent sponsored payments, denying service to legitimate payers once it is empty. MPP.…

Allocation of Resources Without Limits or Throttling in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet through concurrent sponsored payments, denying service to legitimate payers once it is empty. MPP.…

▾ Twilightzenhive · machine_payments_protocolEPSS 0.59%via NVD
CVE-2026-61712Low
1mo ago

BuildKit has a possible runtime DoS via unbounded group parsing

BuildKit has a possible runtime DoS via unbounded group parsing

▾ Sunlitmoby · github.com/moby/buildkitEPSS 0.53%via OSV
CVE-2026-49870Medium· 5.9
1mo ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.6.1, POST /two-factor has no rate limiting, lockout, or attempt counter, allowing an attacker with valid credentials to submit unlimited TOTP guesses against the three accepte…

▾ Sunlitsnipe · snipe/snipe-itEPSS 0.40%via NVD
CVE-2026-71139Medium· 4.4
1mo ago

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core)

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastr…

▾ Sunlitoracle · vm_virtualboxEPSS 0.17%via NVD
CVE-2026-50142High· 7.5PoC
1mo ago

libheif is a HEIF and AVIF file format decoder and encoder

libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.0, a crafted HEIF sequence accepted by heif_context_read_from_memory() with the msf1 sequence brand can cause unbounded heap allocation. In libheif/sequen…

▾ MidnightEPSS 0.66%via NVD
CVE-2026-74039Medium· 6.5PoC
1mo ago

Wazuh 4.0.0 before 4.14.7 and 5.0.0-beta2 contain a denial of service vulnerability that allows authenticated attackers with allow_run_as enabled to exhaust CPU resources by submitting arbitrarily deeply nested JSON structures to the POS…

Wazuh 4.0.0 before 4.14.7 and 5.0.0-beta2 contain a denial of service vulnerability that allows authenticated attackers with allow_run_as enabled to exhaust CPU resources by submitting arbitrarily deeply nested JSON structures to the POS…

▾ Twilightwazuh · wazuhEPSS 0.56%via NVD
CVE-2026-75841Medium· 4.3
1mo ago

ArcadeDB before 26.8.1 contains a denial of service vulnerability in the Cypher range() function that allows authenticated users to exhaust server heap memory

ArcadeDB before 26.8.1 contains a denial of service vulnerability in the Cypher range() function that allows authenticated users to exhaust server heap memory. Attackers can submit oversized range() expressions with large bounds to trigg…

▾ SunlitEPSS 0.37%via NVD
CVE-2026-53423Medium
1mo ago

membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion

membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion

▾ Sunlitmembrane_mp4_plugin · membrane_mp4_pluginEPSS 0.18%via GHSA
CVE-2026-69219High· 7.5
1mo ago

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.1, src/main/java/com/rabbitmq/client/impl/ValueReader.java uses ValueReader.readBytes to accept a wire-…

▾ Twilightrabbitmq · com.rabbitmq:amqp-clientEPSS 0.73%via NVD
CVE-2026-52732Medium· 5.3
1mo ago

ZEBRA is a Zcash node written entirely in Rust

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, one unauthenticated P2P peer can monopolize all 25 MAX_INBOUND_CONCURRENCY slots in Zebra's inbound mempool download and verification pipeline. In zebrad/src/components/memp…

▾ Sunlitzebrad · zebradEPSS 0.51%via NVD
CVE-2026-75050High· 7.1
1mo ago

In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS attack was possible via crafted type parameters

In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS attack was possible via crafted type parameters

▾ Twilightjetbrains · youtrackEPSS 1.1%via NVD
CVE-2026-71486Medium· 4.3
1mo ago

vLLM is an inference and serving engine for large language models

vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the /v1/completions/derender and /v1/chat/completions/derender endpoints accept caller-supplied GenerateResponse objects whose generate_responses, choice…

▾ Sunlitvllm · vllmEPSS 0.47%via NVD
GHSA-j659-8xh6-5pq5High
1mo ago

atomic-agents-stack: Parallel helper/delegate batch reserves $0 for models absent from the pricing table, bypassing the cost-cap fan-out guard

atomic-agents-stack: Parallel helper/delegate batch reserves $0 for models absent from the pricing table, bypassing the cost-cap fan-out guard

▾ Twilightatomic-agents-stack · atomic-agents-stackvia GHSA
CVE-2026-47683High· 7.5
1mo ago

vm2 is an open source vm/sandbox for Node.js

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, the bufferAllocLimit enforcement in lib/setup-sandbox.js does not cover Buffer.concat(list, totalLength) or Buffer.from(arrayLike) with an attacker-controlled length, allowin…

▾ Twilightvm2 · vm2EPSS 0.54%via NVD
GHSA-v836-6xw4-9cx3High· 7.5
1mo ago

vm2 has Memory Exhaustion DoS via bufferAllocLimit Bypass

vm2 has Memory Exhaustion DoS via bufferAllocLimit Bypass

▾ Twilightvm2 · vm2via GHSA
CVE-2026-59902High· 7.5
1mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.sctp.SctpMessageCompletionHandler limits incomplete messages and fragment counts but not maxBufferedByt…

▾ Twilightnetty · nettyEPSS 0.67%via NVD
CVE-2026-64868High· 7.5
1mo ago

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.11, POST /api/stripe/webhook, POST /api/creem/webhook, and POST /api/waffo/webhook read and log full request bodie…

▾ TwilightQuantumNous · github.com/QuantumNous/new-apiEPSS 0.64%via NVD
CVE-2026-73062High· 7.5
1mo ago

Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability in the array multiplication operator that allocates memory without enforcing LoopLimit or overflow-safe arithmetic checks

Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability in the array multiplication operator that allocates memory without enforcing LoopLimit or overflow-safe arithmetic checks. Attackers can supply a large intege…

▾ TwilightEPSS 0.49%via NVD
CVE-2026-19474High· 7.5
1mo ago

@fastify/multipart is a multipart form-data parser for Fastify

@fastify/multipart is a multipart form-data parser for Fastify. In versions from 3.0.0 up to but not including 10.1.1, request.saveRequestFiles() can leave completed temporary files on disk when a client disconnects while the parser is a…

▾ TwilightEPSS 0.49%via NVD
CVE-2026-72838Medium· 6.5
1mo ago

FileBrowser versions before 2.63.19 fail to enforce the declared Upload-Length in the TUS resumable-upload PATCH endpoint, allowing authenticated users to write arbitrary data to disk

FileBrowser versions before 2.63.19 fail to enforce the declared Upload-Length in the TUS resumable-upload PATCH endpoint, allowing authenticated users to write arbitrary data to disk. Attackers can send oversized request bodies that exc…

▾ SunlitEPSS 0.53%via NVD
CVE-2026-10740Medium· 5.3
1mo ago

s2n-quic has excessive memory allocation

s2n-quic has excessive memory allocation

▾ Sunlits2n-quic · s2n-quicEPSS 0.29%via GHSA
CVE-2026-46603High· 7.5
1mo ago

golang.org/x/image/vp8l: golang.org/x/image/vp8l: Denial of Service via excessive memory allocation (CVE-2026-46603)

A flaw was found in golang.org/x/image/vp8l. A remote attacker can cause a denial of service by providing a specially crafted VP8L image. This image, containing many unused Huffman tree groups, leads to excessive memory allocation during V…

▾ TwilightRed Hat · Red Hat Advanced Cluster Management for Kubernetes 2.16EPSS 0.75%via CSAF
CVE-2026-73566High· 7.5
1mo ago

node-tar is a tar archive manipulation library for Node.js

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.21, node-tar's filesFilter in src/list.ts uses the recursive mapHas helper to walk an archive entry path upward with path.dirname() and no segment cap when tar.t(..…

▾ TwilightRed Hat · Red Hat OpenShift Dev Spaces 3.30EPSS 0.53%via NVD
CVE-2026-73565Medium· 5.3
1mo ago

@hono/node-server allows running the Hono application on Node.js

@hono/node-server allows running the Hono application on Node.js. From 2.0.0 until 2.0.10, a WebSocket upgrade request to an upgradeWebSocket route with a missing or malformed Sec-WebSocket-Key header causes src/websocket.ts to retain th…

▾ Sunlithonojs · node-serverEPSS 0.53%via NVD
CVE-2026-70464High· 7.5
1mo ago

rsync daemon 2.0.0 before 3.5.0 contains a denial of service vulnerability that allows unauthenticated remote attackers to exhaust daemon connection slots by stalling the handshake process before or after module selection without trigger…

rsync daemon 2.0.0 before 3.5.0 contains a denial of service vulnerability that allows unauthenticated remote attackers to exhaust daemon connection slots by stalling the handshake process before or after module selection without trigger…

▾ TwilightRed Hat · Red Hat Enterprise Linux BaseOS (v. 10)EPSS 0.78%via NVD
CVE-2026-70453High· 7.5
1mo ago

rsync before 3.5.0 contains an algorithmic complexity vulnerability in the hash_search() function that allows a remote attacker to cause a denial of service by delivering a carefully constructed file list

rsync before 3.5.0 contains an algorithmic complexity vulnerability in the hash_search() function that allows a remote attacker to cause a denial of service by delivering a carefully constructed file list. A sender can exploit the quadra…

▾ TwilightRed Hat · Red Hat Enterprise Linux BaseOS (v. 10)EPSS 0.75%via NVD
CVE-2026-56860High· 7.5
1mo ago

Avoid quadratic complexity in resolvePath in net/url

Avoid quadratic complexity in resolvePath in net/url

▾ Twilightstdlib · stdlibEPSS 0.55%via OSV
CVE-2026-56853High· 7.5
1mo ago

net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853)

A flaw was found in the `net/http` component of the Go standard library. When a server is configured to support unencrypted HTTP/2, it reads initial bytes from new connections to detect the HTTP/2 client preface. However, the `ReadHeaderTi…

▾ TwilightRed Hat · Red Hat OpenShift Container Platform 4.22EPSS 0.57%via CSAF
CVE-2026-48702High· 7.5
1mo ago

Rekor is a software supply chain transparency log

Rekor is a software supply chain transparency log. Starting in version 0.3.0 and prior to version 1.5.2, the `Package.Unmarshal()` function in `pkg/types/alpine/apk.go` decompresses the signature and control gzip members of an APK file i…

▾ TwilightRed Hat · Red Hat Hardened ImagesEPSS 0.46%via NVD
CVE-2026-63299Critical· 9.9
1mo ago

An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume limits

An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume limits. Two related code paths fail to verify resource limits during volume operations: the storagePoolVolumeTypePostMove f…

▾ Midnightcanonical · lxdEPSS 0.59%via NVD
CWE-770 vulnerabilities (CVEs) — page 9 · VulnSea