CWE-1325: Improperly Controlled Sequential Memory Allocation
The product manages a group of objects or resources and performs a separate memory allocation for each object, but it does not properly limit the total amount of memory that is consumed by all of the combined objects.
19 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-24819 — An out-of-memory (OOM) issue in foxinmy/weixin4j
- CVE-2026-34183 — Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler
- CVE-2026-13056 — A user with read access can cause a DoS by executing a specifically crafted query to consume a large amount of RAM
- CVE-2026-8199 — Post-auth memory exhaustion via bitwise match expressions
- CVE-2026-54081 — veraPDF Parser DoS via PostScript Type 1 Font Programs
- CVE-2026-54080 — veraPDF Parser DoS via PostScript CMap Streams
- CVE-2025-13945 — Improperly Controlled Sequential Memory Allocation in Wireshark
- CVE-2026-18772 — Improper input validation vulnerability in Samsung Open Source rlottie allows Oversized Serialized Data Payloads.
- CVE-2026-6869 — Improperly Controlled Sequential Memory Allocation in Wireshark
- CVE-2026-6867 — Improperly Controlled Sequential Memory Allocation in Wireshark
- CVE-2026-6535 — Improperly Controlled Sequential Memory Allocation in Wireshark
- CVE-2026-6533 — Improperly Controlled Sequential Memory Allocation in Wireshark
- CVE-2026-71436 — Mermaid XY Charts are vulnerable to an infinite loop DoS
Recently published
- CVE-2026-71436 — Mermaid XY Charts are vulnerable to an infinite loop DoS
- CVE-2026-18772 — Improper input validation vulnerability in Samsung Open Source rlottie allows Oversized Serialized Data Payloads.
- CVE-2026-54081 — veraPDF Parser DoS via PostScript Type 1 Font Programs
- CVE-2026-54080 — veraPDF Parser DoS via PostScript CMap Streams
- CVE-2026-13056 — A user with read access can cause a DoS by executing a specifically crafted query to consume a large amount of RAM
- CVE-2026-34183 — Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler
- CVE-2026-8199 — Post-auth memory exhaustion via bitwise match expressions
- CVE-2026-6535 — Improperly Controlled Sequential Memory Allocation in Wireshark
- CVE-2026-6533 — Improperly Controlled Sequential Memory Allocation in Wireshark
- CVE-2026-6869 — Improperly Controlled Sequential Memory Allocation in Wireshark
- CVE-2026-6867 — Improperly Controlled Sequential Memory Allocation in Wireshark
- CVE-2026-24819 — An out-of-memory (OOM) issue in foxinmy/weixin4j
- CVE-2025-13945 — Improperly Controlled Sequential Memory Allocation in Wireshark