VulnSea

CWE-789

CVEs classified under CWE-789, newest first.

76 CVEsRSS

CVE-2026-55407Medium
1mo ago

Buffa Vulnerable to Memory Exhaustion Denial of Service in decode_unknown_field via Unbounded Allocation

Buffa Vulnerable to Memory Exhaustion Denial of Service in decode_unknown_field via Unbounded Allocation

▾ Sunlitbuffa · buffaEPSS 0.76%via GHSA
CVE-2026-81692High· 7.5
1mo ago

openssl_encrypt (pip: openssl-encrypt) versions 1.4.8 and earlier fail to validate the 36-bit STREAMINFO total_samples field of FLAC files before using it to size an allocation (np.random.randint(size=(total_samples, channels)))

openssl_encrypt (pip: openssl-encrypt) versions 1.4.8 and earlier fail to validate the 36-bit STREAMINFO total_samples field of FLAC files before using it to size an allocation (np.random.randint(size=(total_samples, channels))). A ~50-b…

▾ TwilightEPSS 0.49%via NVD
CVE-2026-77354High· 7.5
1mo ago

kin-openapi is a Go project for handling OpenAPI files

kin-openapi is a Go project for handling OpenAPI files. From 0.124.0 until 0.142.0, openapi3filter.sliceMapToSlice in openapi3filter/req_resp_decoder.go converts attacker-controlled sparse indexes from a deepObject query parameter into a…

▾ Twilightgetkin · github.com/getkin/kin-openapiEPSS 0.52%via NVD
CVE-2026-44253Medium· 4.9PoC
1mo ago

Wazuh is a free and open source platform used for threat prevention, detection, and response

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 3.9.0 until 4.14.5 and 5.0.0-beta2, the Wazuh cluster protocol in framework/wazuh/core/cluster/common.py allows an authenticated cluster n…

▾ Twilightwazuh · wazuhEPSS 0.61%via NVD
CVE-2026-69219High· 7.5
1mo ago

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.1, src/main/java/com/rabbitmq/client/impl/ValueReader.java uses ValueReader.readBytes to accept a wire-…

▾ Twilightrabbitmq · com.rabbitmq:amqp-clientEPSS 0.73%via NVD
CVE-2026-72656Medium· 6.5
1mo ago

Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query processing of Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130)

Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query processing of Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user able to submit ES|QL queries could send a spec…

▾ Sunlitelastic · elasticsearchEPSS 0.42%via NVD
CVE-2026-15567High· 7.5
1mo ago

A flaw was found in Wildfly

A flaw was found in Wildfly. A remote unauthenticated attacker can trigger OutOfMemoryError as CSIv2Util's GSS token decoder reads an attacker-controlled length field without bounds checking and attempts to allocate a byte array of that …

▾ TwilightRed Hat · org.jboss.eap/wildfly-iiop-openjdkEPSS 0.53%via NVD
CVE-2026-17535Medium· 6.2
1mo ago

Velociraptor's NTFS parsing library mishandles several out of bound and memory exhaustion bugs which may be triggered by maliciously crafted NTFS images. Typically Velociraptor's NTFS parser is used on live NTFS filesystems, limiting th…

Velociraptor's NTFS parsing library mishandles several out of bound and memory exhaustion bugs which may be triggered by maliciously crafted NTFS images. Typically Velociraptor's NTFS parser is used on live NTFS filesystems, limiting th…

▾ SunlitEPSS 0.16%via NVD
CVE-2026-66733High· 7.5
1mo ago

Sonic 3 A.I.R

Sonic 3 A.I.R. before commit 2492d18 contains an unbounded memory allocation vulnerability in ReceivedPacketCache::enqueuePacket() that allows unauthenticated remote attackers to crash the server process by sending a crafted UDP packet w…

▾ TwilightEPSS 1.6%via NVD
CVE-2026-70377High· 7.5
1mo ago

imagecli's pipeline operation (Scale::apply in src/image_ops.rs) computes output width/height as (dimension as f32 * ratio) as u32 with no upper-bound validation on the CLI-supplied ratio, which is parsed via nom::number::complete::float…

imagecli's pipeline operation (Scale::apply in src/image_ops.rs) computes output width/height as (dimension as f32 * ratio) as u32 with no upper-bound validation on the CLI-supplied ratio, which is parsed via nom::number::complete::float…

▾ TwilightEPSS 0.46%via NVD
CVE-2026-67589High· 7.5
1mo ago

A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to ver…

A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to ver…

▾ Twilightapache · qpid_protonj2EPSS 0.77%via NVD
CVE-2026-67551High· 7.5
1mo ago

pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to …

pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to …

▾ Twilightapache · qpid_proton-dotnetEPSS 0.77%via NVD
CVE-2026-71314High· 7.5
1mo ago

Nuxt is an open-source web development framework for Vue.js

Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an unauthenticated attacker can use a server island v-for prop, including vforToArray and , to trigger unbounded SSR memory allocation until…

▾ Twilightnuxt · nuxtEPSS 0.66%via NVD
CVE-2026-69702Medium· 6.5
1mo ago

SnailJob 1.7.0 contains a denial of service vulnerability in the FuryUtil.deserialize helper that allows authenticated attackers to crash the server by supplying a crafted Zstandard-compressed payload with an inflated frame_content_size …

SnailJob 1.7.0 contains a denial of service vulnerability in the FuryUtil.deserialize helper that allows authenticated attackers to crash the server by supplying a crafted Zstandard-compressed payload with an inflated frame_content_size …

▾ Sunlitaizuda · SnailJob (snail-job)EPSS 0.55%via NVD
CVE-2026-14682High· 7.5
1mo ago

In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read

In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips …

▾ Twilightbouncycastle · bc-javaEPSS 0.33%via NVD
CVE-2026-59649High· 7.5
1mo ago

In Bouncy Castle for Java before 1.85, OpenPGP user-attribute subpacket length bounded only by JVM max memory

In Bouncy Castle for Java before 1.85, OpenPGP user-attribute subpacket length bounded only by JVM max memory. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1…

▾ TwilightRed Hat · Red Hat JBoss Enterprise Application Platform 7EPSS 0.49%via NVD
CVE-2026-59646None
1mo ago

In Bouncy Castle for Java before 1.85, DTLS handshake reassembler allocates buffer from unchecked 24-bit length

In Bouncy Castle for Java before 1.85, DTLS handshake reassembler allocates buffer from unchecked 24-bit length. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bctls-fip…

▾ SunlitEPSS 0.62%via NVD
CVE-2026-12185None
1mo ago

In Bouncy Castle for Java before 1.85, BKS/UBER keystore allocates from untrusted lengths before integrity check

In Bouncy Castle for Java before 1.85, BKS/UBER keystore allocates from untrusted lengths before integrity check. This issue also affects Bouncy Castle for Java LTS before 2.73.12.

▾ SunlitEPSS 0.29%via NVD
CVE-2026-52857Medium· 5.5
1mo ago

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, unbounded json, yaml, and xml configuration-file parsers in parser.go can process an oversized non-file parser configur…

▾ Sunlitpterodactyl · github.com/pterodactyl/wingsEPSS 0.16%via NVD
CVE-2026-55768None
1mo ago

GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser

GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. Prior to version 1.11, the built-in WebSocket server narrows a 64-bit extended frame length into the signed 3…

▾ SunlitEPSS 0.47%via NVD
CVE-2026-54638High· 7.5
2mo ago

gotd/td is a T Telegram MTProto API client in Go

gotd/td is a T Telegram MTProto API client in Go. Prior to 0.145.1, proto.UnencryptedMessage.Decode in proto/unencrypted_message.go read attacker controlled dataLen from an unauthenticated MTProto unencrypted packet and allocated make([]…

▾ Twilightgotd · github.com/gotd/tdEPSS 0.63%via NVD
CVE-2026-59938Medium
2mo ago

pypdf: Possible large memory usage for wrong image dimensions

pypdf: Possible large memory usage for wrong image dimensions

▾ Sunlitpypdf · pypdfEPSS 0.52%via OSV
CVE-2026-65315High· 7.5
2mo ago

Ollama Remote Denial of Service via Attacker-Controlled Allocation in GGUF Metadata Parser

Ollama (HEAD f0078ae) contains an uncontrolled memory allocation vulnerability in the GGUF metadata parser that allows remote attackers to crash the server by supplying a crafted GGUF file with attacker-controlled length and count fields…

▾ TwilightOllama · OllamaEPSS 0.81%via CVEORG
CVE-2025-71395None
2mo ago

SurrealDB versions before 2.2.2 contain a memory exhaustion vulnerability in the string::replace function that fails to restrict resulting string length when using regex patterns

SurrealDB versions before 2.2.2 contain a memory exhaustion vulnerability in the string::replace function that fails to restrict resulting string length when using regex patterns. An authenticated attacker can craft a malicious query to …

▾ SunlitEPSS 0.45%via NVD
CVE-2026-59204High· 7.5
2mo ago

Pillow: Pillow: Denial of Service via crafted JPEG2000 image (CVE-2026-59204)

A flaw was found in Pillow, a Python imaging library. A remote attacker could exploit this vulnerability by providing a specially crafted JPEG2000 image file. Due to incorrect calculation of memory requirements for image tiles, processing …

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.66%via CSAF
CVE-2026-40378High· 7.5
2mo ago

Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.

Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.

▾ Twilightmicrosoft · windows_10_1607EPSS 1.2%via NVD
CVE-2026-54448High
2mo ago

Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser

Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser

▾ Twilightaquasecurity · github.com/aquasecurity/trivyEPSS 0.44%via GHSA
CVE-2026-55213High· 7.5
2mo ago

h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3

h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit edd7a120bfc4af11ac0cbebce2a43cc1f93f9af1, when h2o processes a QPACK instruction sent from the peer over HTTP/3, lib/http3/qpack.c might allocate an on-s…

▾ TwilightEPSS 0.49%via NVD
CVE-2026-55781NonePoC
2mo ago

NanaZip is the 7-Zip derivative intended for the modern Windows experience

NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's UFS and FFS image handler in NanaZip.Codecs.Archive.Ufs.cpp validates the superblock block size only against the MINBSIZE lower bo…

▾ TwilightEPSS 0.16%via NVD
CVE-2026-55079Medium· 4.9
2mo ago

Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service

Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service

▾ Sunlitcoder · github.com/coder/coder/v2EPSS 0.61%via GHSA
CWE-789 vulnerabilities (CVEs) — page 2 · VulnSea