VulnSea

CWE-789

CVEs classified under CWE-789, newest first.

61 CVEsRSS

CVE-2026-62370Medium· 6.5
today

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.0.0 until 1.21.2, 1.22.2, and 1.23.1, Reader.Read in pkg/viaduct/pkg/packer trusts the 32-bit PackageHea…

Sunlitkubeedge · kubeedgevia NVD
CVE-2026-47321High· 7.5
today

The CompressionFilter class uses ZLib to deflate and inflate data sent and received

The CompressionFilter class uses ZLib to deflate and inflate data sent and received. When we inflate incoming data, the filter does not control the resulting size, and create a buffer no matter what. Some compressed data may have a comp…

TwilightApache Software Foundation · org.apache.mina:mina-filter-compressionEPSS 0.29%via NVD
CVE-2026-77301High· 7.5PoC
3d ago

adm-zip is a JavaScript library for creating and extracting ZIP archives in Node.js

adm-zip is a JavaScript library for creating and extracting ZIP archives in Node.js. Prior to 0.6.1, getData() in zipEntry.js trusts an entry's central-directory uncompressed size and allocates output memory before validating that value …

Midnightadm-zip · adm-zipEPSS 0.41%via NVD
CVE-2026-93019Critical· 9.1PoC
3d ago

Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_palette_read. The reader unpacks the two-byte colour map length into a signed short, so a length of 32768 or more beco…

Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_palette_read. The reader unpacks the two-byte colour map length into a signed short, so a length of 32768 or more beco…

AbyssalEPSS 0.61%via NVD
CVE-2026-93307Medium· 4.3
4d ago

A vulnerability has been found in O-RAN-SC SMO OAM 2025-06-10

A vulnerability has been found in O-RAN-SC SMO OAM 2025-06-10. Affected is an unknown function of the component VES Collector. Such manipulation of the argument additionalFields.padding leads to uncontrolled memory allocation. The attack…

SunlitO-RAN-SC · SMO OAMEPSS 0.30%via NVD
CVE-2026-85715High· 7.5PoC
4d ago

ExifReader is a JavaScript Exif information parser

ExifReader is a JavaScript Exif information parser. Prior to 4.41.1, ExifReader parses attacker-controlled HEIC or AVIF ISO-BMFF files in getItems() within src/image-header-iso-bmff-iloc.js and trusts iloc itemCount and extentCount value…

Midnightmattiasw · ExifReaderEPSS 0.41%via NVD
CVE-2026-20295High· 8.6
5d ago

A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software and Cisco Secure FTD Software could allow an unauthenticated, remote attacker to exhaust the available memory of an affected device. This…

A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software and Cisco Secure FTD Software could allow an unauthenticated, remote attacker to exhaust the available memory of an affected device. This…

TwilightCisco · Cisco Secure Firewall Management Center (FMC)EPSS 0.55%via NVD
CVE-2026-77410High· 8.9
5d ago

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channel.recvContent in channel.go preallocates the message body slice with the uint64 ch.header.Size value supplied by an AMQP content header without capping the allocation …

Twilightrabbitmq · amqp091-goEPSS 0.41%via NVD
CVE-2026-91752High· 7.5PoC
6d ago

GNU libextractor before 1.15 contains a stack-based buffer overflow vulnerability in the process_star_office function that sizes a variable-length stack array from attacker-controlled OLE2 stream data

GNU libextractor before 1.15 contains a stack-based buffer overflow vulnerability in the process_star_office function that sizes a variable-length stack array from attacker-controlled OLE2 stream data. Attackers can craft malicious StarO…

MidnightGNU · libextractorEPSS 0.41%via NVD
CVE-2026-55149High· 7.5PoC
6d ago

Vouch Proxy is an SSO and OAuth/OIDC login solution for Nginx using the auth_request module

Vouch Proxy is an SSO and OAuth/OIDC login solution for Nginx using the auth_request module. Prior to 0.48.0, Cookie in pkg/cookie/cookie.go parses the total part count from an attacker-controlled multipart cookie name and passes the val…

Midnightvouch · vouch-proxyEPSS 0.40%via NVD
CVE-2026-82435Critical· 9.8
1w ago

Description The worker's Netty message decoder is installed ahead of the SASL authentication handlers in the pipeline and acts on frames before any authentication has taken place

Description The worker's Netty message decoder is installed ahead of the SASL authentication handlers in the pipeline and acts on frames before any authentication has taken place. It allocated buffers sized from a length field carried i…

MidnightApache Software Foundation · org.apache.storm:storm-clientEPSS 0.61%via NVD
CVE-2026-53716Medium· 6.5
1w ago

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, getFileFromGZ in internal/wasm/httpfetcher.go calls io.ReadAll on a gzip.Reader without l…

Sunlitenvoyproxy · gatewayEPSS 0.69%via NVD
CVE-2026-53717Medium· 6.5
1w ago

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, internal/wasm/imagefetcher.go follows tenant-controlled EnvoyExtensionPolicy spec.wasm[].…

Sunlitenvoyproxy · gatewayEPSS 0.71%via NVD
CVE-2026-67211High· 7.5
1w ago

OOM Denial of Service via Unbounded Map Pre-Sizing in Apache OpenNLP SymSpellModelSerializer Versions Affected: - 3.0.0-M4 - 3.0.0-M5 (The opennlp-spellcheck extension was introduced in 3.0.0-M4

OOM Denial of Service via Unbounded Map Pre-Sizing in Apache OpenNLP SymSpellModelSerializer Versions Affected: - 3.0.0-M4 - 3.0.0-M5 (The opennlp-spellcheck extension was introduced in 3.0.0-M4. Releases 1.x and 2.x do not contain t…

Twilightapache · opennlpEPSS 0.47%via NVD
CVE-2026-89092Medium· 4.2
1w ago

glibc: nscd stack overflow leads to degraded DNS resolution (CVE-2026-89092)

A flaw was found in glibc, specifically within the nscd service. A remote attacker, operating a malicious Domain Name System (DNS) server, could send an overly large DNS response. This could trigger a stack overflow in the nscd service, ca…

SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.24%via CSAF
CVE-2026-88045High· 7.5PoC
1w ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.75.0 until 1.75.1, the serve S3 streamed multipart path in cmd/serve/s3/multipart.go passes attacker-controlled contentL…

Midnightrclone · rcloneEPSS 0.53%via NVD
CVE-2026-83530Medium· 6.9
1w ago

A user could provide an expression whose string length is longer than the ParserExpressionSizeLimit() configured on the CEL environment, and a memory allocation would occur proportional to the size of the input before the limit would be …

A user could provide an expression whose string length is longer than the ParserExpressionSizeLimit() configured on the CEL environment, and a memory allocation would occur proportional to the size of the input before the limit would be …

SunlitGoogle · cel-goEPSS 0.21%via NVD
CVE-2026-86776Low· 3.3PoC
1w ago

KeePass versions 2.35 through 2.61.1 fail to validate KDBX header field sizes before memory allocation in the ReadHeaderField function

KeePass versions 2.35 through 2.61.1 fail to validate KDBX header field sizes before memory allocation in the ReadHeaderField function. Attackers can craft a malicious KDBX file declaring excessive header field lengths to trigger allocat…

TwilightKeePass · KeePassEPSS 0.12%via NVD
CVE-2026-85201Medium· 6.8
2w ago

In Eclipse Ankaios versions 0.1.0 through 1.0.1, the agent does not limit the length declared by a workload in a length-delimited protobuf message received through the Control Interface FIFO

In Eclipse Ankaios versions 0.1.0 through 1.0.1, the agent does not limit the length declared by a workload in a length-delimited protobuf message received through the Control Interface FIFO. A workload granted Control Interface access c…

SunlitEclipse Foundation · Eclipse AnkaiosEPSS 0.11%via NVD
CVE-2026-19204High· 8.7
2w ago

A client may send a WebSocket frame with an unknown opcode and a very large declared payload length, causing Jetty to attempt a large memory allocation and potentially exhaust the JVM heap. This occurs when auto-fragmentation is enab…

A client may send a WebSocket frame with an unknown opcode and a very large declared payload length, causing Jetty to attempt a large memory allocation and potentially exhaust the JVM heap. This occurs when auto-fragmentation is enab…

TwilightEclipse Foundation · Eclipse JettyEPSS 0.29%via NVD
CVE-2026-85445High· 7.5
2w ago

MOOS-IvP through 24.8.1 contains a denial of service vulnerability in the Demuxer::addMuxPacket() function that trusts the packet count declared in mux headers without validation

MOOS-IvP through 24.8.1 contains a denial of service vulnerability in the Demuxer::addMuxPacket() function that trusts the packet count declared in mux headers without validation. Attackers can declare arbitrarily large packet counts to …

TwilightEPSS 0.35%via NVD
CVE-2026-85442High· 7.5
2w ago

MOOS core-moos through 10.4.0 fails to validate packet length declarations in CMOOSCommPkt::OnBytesWritten(), allowing unauthenticated attackers to trigger unbounded buffer allocation by sending crafted wire packets

MOOS core-moos through 10.4.0 fails to validate packet length declarations in CMOOSCommPkt::OnBytesWritten(), allowing unauthenticated attackers to trigger unbounded buffer allocation by sending crafted wire packets. Attackers can send p…

TwilightEPSS 0.41%via NVD
CVE-2026-55407Medium
3w ago

Buffa Vulnerable to Memory Exhaustion Denial of Service in decode_unknown_field via Unbounded Allocation

Buffa Vulnerable to Memory Exhaustion Denial of Service in decode_unknown_field via Unbounded Allocation

Sunlitbuffa · buffaEPSS 0.76%via GHSA
CVE-2026-77354High· 7.5
1mo ago

kin-openapi is a Go project for handling OpenAPI files

kin-openapi is a Go project for handling OpenAPI files. From 0.124.0 until 0.142.0, openapi3filter.sliceMapToSlice in openapi3filter/req_resp_decoder.go converts attacker-controlled sparse indexes from a deepObject query parameter into a…

Twilightgetkin · github.com/getkin/kin-openapiEPSS 0.30%via NVD
CVE-2026-44253Medium· 4.9PoC
1mo ago

Wazuh is a free and open source platform used for threat prevention, detection, and response

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 3.9.0 until 4.14.5 and 5.0.0-beta2, the Wazuh cluster protocol in framework/wazuh/core/cluster/common.py allows an authenticated cluster n…

Twilightwazuh · wazuhEPSS 0.51%via NVD
CVE-2026-69219High
1mo ago

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.1, src/main/java/com/rabbitmq/client/impl/ValueReader.java uses ValueReader.readBytes to accept a wire-…

Twilightrabbitmq · com.rabbitmq:amqp-clientEPSS 0.42%via NVD
CVE-2026-72656Medium· 6.5
1mo ago

Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query processing of Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130)

Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query processing of Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user able to submit ES|QL queries could send a spec…

Sunlitelastic · elasticsearchEPSS 0.30%via NVD
CVE-2026-15567High· 7.5
1mo ago

A flaw was found in Wildfly

A flaw was found in Wildfly. A remote unauthenticated attacker can trigger OutOfMemoryError as CSIv2Util's GSS token decoder reads an attacker-controlled length field without bounds checking and attempts to allocate a byte array of that …

TwilightRed Hat · eap7-activemq-artemisEPSS 0.47%via NVD
CVE-2026-17535Medium· 6.2
1mo ago

Velociraptor's NTFS parsing library mishandles several out of bound and memory exhaustion bugs which may be triggered by maliciously crafted NTFS images. Typically Velociraptor's NTFS parser is used on live NTFS filesystems, limiting th…

Velociraptor's NTFS parsing library mishandles several out of bound and memory exhaustion bugs which may be triggered by maliciously crafted NTFS images. Typically Velociraptor's NTFS parser is used on live NTFS filesystems, limiting th…

SunlitEPSS 0.12%via NVD
CVE-2026-70377High· 7.5
1mo ago

imagecli's pipeline operation (Scale::apply in src/image_ops.rs) computes output width/height as (dimension as f32 * ratio) as u32 with no upper-bound validation on the CLI-supplied ratio, which is parsed via nom::number::complete::float…

imagecli's pipeline operation (Scale::apply in src/image_ops.rs) computes output width/height as (dimension as f32 * ratio) as u32 with no upper-bound validation on the CLI-supplied ratio, which is parsed via nom::number::complete::float…

TwilightEPSS 0.36%via NVD
CWE-789 vulnerabilities (CVEs) · VulnSea