VulnSea

CWE-789

CVEs classified under CWE-789, newest first.

76 CVEsRSS

CVE-2026-48502High
3mo ago

MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflows

MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflows

▾ TwilightMessagePack · MessagePackEPSS 0.44%via GHSA
GHSA-ch3q-cw5r-f4hgMedium
3mo ago

ConnectBot SSH Client Library: Unbounded SSH field lengths can cause excessive memory allocation

ConnectBot SSH Client Library: Unbounded SSH field lengths can cause excessive memory allocation

▾ Sunlitconnectbot · org.connectbot.sshlib:sshlibvia GHSA
GHSA-vc8p-8pxg-rfwgMedium
3mo ago

ConnectBot SSH Client Library: Excessive allocation and integer overflow in DER private-key parsing

ConnectBot SSH Client Library: Excessive allocation and integer overflow in DER private-key parsing

▾ Sunlitconnectbot · org.connectbot.sshlib:sshlibvia GHSA
CVE-2026-52759Medium· 5.5PoC
3mo ago

Ghidra < 12.1.1 - Denial of Service via Uncontrolled Memory Allocation in Mach-O Parser

Ghidra before 12.1.1 contains an uncontrolled memory allocation vulnerability in the Mach-O binary parser that allows attackers to cause denial of service. An attacker can supply a crafted Mach-O binary with an arbitrarily large ncmds lo…

▾ TwilightGhidra · GhidraEPSS 0.16%via CVEORG
CVE-2026-47734Medium· 5.7
3mo ago

Dulwich has unbounded memory allocation in receive-pack from crafted thin packs

Dulwich has unbounded memory allocation in receive-pack from crafted thin packs

▾ Sunlitdulwich · dulwichEPSS 0.33%via GHSA
CVE-2026-8485Medium· 5.9
4mo ago

Uncontrolled Memory Allocation vulnerability in Progress Software MOVEit Automation allows Excessive Allocation. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.

Uncontrolled Memory Allocation vulnerability in Progress Software MOVEit Automation allows Excessive Allocation. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.

▾ Sunlitprogress · moveit_automationEPSS 0.43%via NVD
CVE-2026-42582High· 7.5
4mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute new byt…

▾ Twilightnetty · nettyEPSS 0.49%via NVD
CVE-2026-43868Medium· 5.3
4mo ago

Memory Allocation with Excessive Size Value vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

Memory Allocation with Excessive Size Value vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

▾ Sunlitapache · thriftEPSS 1.2%via NVD
CVE-2026-42154High· 7.5PoC
4mo ago

Prometheus is an open-source monitoring system and time series database

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a snappy-compressed request body before…

▾ Midnightprometheus · prometheusEPSS 0.89%via NVD
CVE-2026-42440High· 7.5
4mo ago

OOM Denial of Service via Unbounded Array Allocation in Apache OpenNLP AbstractModelReader  Versions Affected:  before 1.9.5 before 2.5.9 before 3.0.0-M3  Description: The AbstractModelReader methods getOutcomes(), getOutcomePatter…

OOM Denial of Service via Unbounded Array Allocation in Apache OpenNLP AbstractModelReader  Versions Affected:  before 1.9.5 before 2.5.9 before 3.0.0-M3  Description: The AbstractModelReader methods getOutcomes(), getOutcomePatter…

▾ Twilightapache · opennlpEPSS 1.1%via NVD
CVE-2026-24030Medium· 5.3
6mo ago

An attacker might be able to trick DNSdist into allocating too much memory while processing DNS over QUIC or DNS over HTTP/3 payloads, resulting in a denial of service

An attacker might be able to trick DNSdist into allocating too much memory while processing DNS over QUIC or DNS over HTTP/3 payloads, resulting in a denial of service. In setups with a large quantity of memory available this usually res…

▾ Sunlitpowerdns · dnsdistEPSS 0.54%via NVD
CVE-2026-26931Medium· 5.7
6mo ago

Memory Allocation with Excessive Size Value (CWE-789) in the Prometheus remote_write HTTP handler in Metricbeat can lead Denial of Service via Excessive Allocation (CAPEC-130).

Memory Allocation with Excessive Size Value (CWE-789) in the Prometheus remote_write HTTP handler in Metricbeat can lead Denial of Service via Excessive Allocation (CAPEC-130).

▾ Sunlitelastic · metricbeatEPSS 0.29%via NVD
CVE-2026-22188Medium· 5.5
8mo ago

The deploy-stub component in Panda3D versions up to and including 1.10.16 contains a denial of service vulnerability due to unbounded stack allocation

The deploy-stub component in Panda3D versions up to and including 1.10.16 contains a denial of service vulnerability due to unbounded stack allocation. The deploy-stub executable allocates argv_copy and argv_copy2 using alloca() based di…

▾ Sunlitcmu · panda3dEPSS 0.20%via NVD
CVE-2025-11579Medium· 5.3PoC
11mo ago

github.com/nwaples/rardecode: RarDecode Out Of Memory Crash (CVE-2025-11579)

A memory exhaustion flaw has been discovered in the golang Rar Decode library (github.com/nwaples/rardecode). Affected versions did not limit the size of an archive and so an attacker could provide a crafted archive to a tool or service bu…

▾ TwilightRed Hat · Red Hat Advanced Cluster Security 4EPSS 0.37%via CSAF
CVE-2025-8696High· 7.5
1y ago

If an unauthenticated user sends a large amount of data to the Stork UI, it may cause memory and disk use problems for the system running the Stork server. This issue affects Stork versions 1.0.0 through 2.3.0.

If an unauthenticated user sends a large amount of data to the Stork UI, it may cause memory and disk use problems for the system running the Stork server. This issue affects Stork versions 1.0.0 through 2.3.0.

▾ TwilightEPSS 0.44%via NVD
CVE-2024-20260High· 8.6
1y ago

Update for September 16, 2026: The original 1.0 version of this advisory was specific to the Cisco Adaptive Security Virtual Appliance (ASAv) and Cisco Secure Firewall Threat Defense Virtual (FTDv) models

Update for September 16, 2026: The original 1.0 version of this advisory was specific to the Cisco Adaptive Security Virtual Appliance (ASAv) and Cisco Secure Firewall Threat Defense Virtual (FTDv) models. However, it was later found tha…

▾ TwilightCisco · Cisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareEPSS 0.59%via NVD
CWE-789 vulnerabilities (CVEs) — page 3 · VulnSea