CWE-770: Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
1,407 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-53521 — BigIP APM Vulnerability
- CVE-2025-11832 — APIs Lack Rate Limiting
- CVE-2026-11972 — tarfile opened in streaming mode mishandles EOF
- CVE-2025-22273 — Lack of rate-limiting in password change mechanism in CyberArk Endpoint Privilege Manager
- CVE-2026-25579 — Navidrome affected by Denial of Service and disk exhaustion via oversized `size` parameter in `/rest/getCoverArt` and `/share/img/<token>` endpoints
- CVE-2025-65015 — joserfc has Possible Uncontrolled Resource Consumption Vulnerability Triggered by Logging Arbitrarily Large JWT Token Payloads
- CVE-2025-27419 — Denial of Service (DoS) in WeGIA due to Recursive Crawling of Dynamic URLs
- CVE-2025-66418 — urllib3 allows an unbounded number of links in the decompression chain
- CVE-2025-11044 — Vulnerability on Automation Runtime my cause DoS Conditions
- CVE-2025-61595 — MANTRA tx gas limit is not enforced in send hooks
- CVE-2025-52568 — NeKernal Multiple Memory Corruption Vulnerabilities in mkfs.hefs
- CVE-2026-15972 — Unauthenticated denial of service via unbounded external gRPC connection acceptance
- CVE-2026-41284 — Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling
- CVE-2025-14870 — Allocation of Resources Without Limits or Throttling in GitLab
- CVE-2026-29609 — OpenClaw < 2026.2.14 - Denial of Service via Unbounded URL-backed Media Fetch
- CVE-2026-33241 — Salvo Affected by Denial of Service via Unbounded Memory Allocation in Form Data Parsing
- CVE-2026-30946 — Parse Server affected by denial-of-service via unbounded query complexity in REST and GraphQL API
- CVE-2026-28478 — OpenClaw < 2026.2.13 - Denial of Service via Unbounded Webhook Request Body Buffering
- CVE-2026-26061 — Fleet's unbounded request body read allows remote Denial of Service
- CVE-2026-24133 — jsPDF Affected by Denial of Service (DoS) via Unvalidated BMP Dimensions in BMPDecoder
Recently published
- CVE-2023-54394 — PocketMine-MP before 4.18.0-ALPHA2 Bandwidth Amplification via InventoryTransactionPacket
- CVE-2026-53937 — MCP Kotlin SDK's unbounded line buffer in StdioServerTransport/StdioClientTransport leads to memory exhaustion (DoS)
- CVE-2026-86075 — n8n: Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration Endpoint
- CVE-2026-82075 — Uncontrolled Resource Consumption in MongoDB Sharded Cluster Router Allows Unauthenticated Denial of Service
- CVE-2026-82054 — Uncontrolled Resource Consumption in MongoDB Server JSON Pointer Parser Leads to Denial of Service
- CVE-2026-62649 — A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The web server does not properly limit or m
- CVE-2026-48888 — WordPress WooCommerce plugin < 11.1.0 - Denial of Service Attack vulnerability
- CVE-2026-86513 — java-json-tools jackson-coreutils JSON Pointer parser TreePointer.java TreePointer.tokensFromInput allocation of resources
- CVE-2026-75808 — Allocation of Resources Without Limits or Throttling in ASUS Armoury Crate allows a local user to cause a denial-of-serv
- CVE-2026-82753 — Unauthenticated authorize requests create unbounded, never-expiring CIMD client rows and cache entries in ash_authentication_oauth2_server
- CVE-2026-86452 — MISP Unauthenticated Mail Endpoints Allow Unbounded Storage Consumption and Request Flooding
- CVE-2025-52657 — HCL MyXalytics is affected by multiple security vulnerabilities.
- CVE-2026-19204 — A client may send a WebSocket frame with an unknown opcode and a very large declared payload length, causing Jetty to at
- CVE-2022-51008 — PocketMine-MP before 4.12.3 Denial of Service via Unauthenticated Sessions
- CVE-2026-85703 — ramon-victor freegpt-webui Jailbreak Mode backend.py getJailbreak allocation of resources
- CVE-2026-84890 — undici vulnerable to Denial of Service via unbounded decompression of compressed responses
- CVE-2026-85664 — Chroma 1.5.9 Unbounded HNSW Index Parameters Memory Exhaustion
- CVE-2026-82728 — Unbounded HTTP/1 status-line and chunk-extension buffering in Mint causes memory-exhaustion DoS
- CVE-2026-82309 — Robots::Validate versions from 0.3.2 before 0.3.11 for Perl allow unbounded outbound DNS queries per validation via a forward-confirmation loop that does not bound the names it queries
- CVE-2026-85584 — SiYuan before v3.8.2 Denial of Service via Auth Throttle