CWE-770: Allocation of Resources Without Limits or Throttling — known CVE vulnerabilities
CVEs classified under CWE-770 (Allocation of Resources Without Limits or Throttling), ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (50)
CVE-2026-63299 — CVSS 9.9 (critical): An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume limits. Two related code…
CVE-2026-82439 — CVSS 9.8 (critical): Description The DRPC server kept a map from function name to request queue and created an entry the first time a function name was seen. No…
CVE-2026-47891 — CVSS 9.8 (critical): A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the maxInMemorySize…
CVE-2026-74878 — CVSS 9.8 (critical): openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force protection that is not shared across workers and…
CVE-2026-31283 — CVSS 9.8 (critical): In Totara LMS v19.1.5 and before, the forgot password API does not implement rate limiting for the target email address. which can be used…
CVE-2020-37067 — CVSS 9.8 (critical): Filetto 1.0 FTP server contains a denial of service vulnerability in the FEAT command processing that allows attackers to crash the…
CVE-2021-47875 — CVSS 9.8 (critical): GeoGebra CAS Calculator 6.0.631.0 contains a denial of service vulnerability that allows attackers to crash the application by generating a…
CVE-2025-11832 — CVSS 9.8 (critical): Allocation of Resources Without Limits or Throttling vulnerability in Azure Access Technology BLU-IC2, Azure Access Technology BLU-IC4…
CVE-2024-44241 — CVSS 9.8 (critical): The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1. An attacker may…
CVE-2021-47137 — CVSS 9.8 (critical): In the Linux kernel, the following vulnerability has been resolved: net: lantiq: fix memory corruption in RX ring In a situation where…
CVE-2022-3439 — CVSS 9.8 (critical): Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0.
CVE-2022-3456 — CVSS 9.8 (critical): Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0.
CVE-2022-29503 — CVSS 9.8 (critical): A memory corruption vulnerability exists in the libpthread linuxthreads functionality of uClibC 0.9.33.2 and uClibC-ng 1.0.40. Thread…
CVE-2019-17067 — CVSS 9.8 (critical): PuTTY before 0.73 on Windows improperly opens port-forwarding listening sockets, which allows attackers to listen on the same port to steal…
CVE-2018-20033 — CVSS 9.8 (critical): A Remote Code Execution vulnerability in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier could allow…
CVE-2017-6713 — CVSS 9.8 (critical): A vulnerability in the Play Framework of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to gain…
CVE-2017-6640 — CVSS 9.8 (critical): A vulnerability in Cisco Prime Data Center Network Manager (DCNM) Software could allow an unauthenticated, remote attacker to log in to the…
CVE-2026-12818: Delta Electronics DVP12SE PLCs are susceptible to a resource allocation vulnerability without limits or throttling (CWE-770) within their…
CVE-2025-22273: Application does not limit the number or frequency of user interactions, such as the number of incoming requests. At the…
CVE-2025-68456 — CVSS 9.1 (critical): Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 3.0.0 through 4.16.16, unauthenticated users…
CVE-2024-38821 — CVSS 9.1 (critical): Spring WebFlux applications that have Spring Security authorization rules on static resources can be bypassed under certain circumstances…
CVE-2024-6037 — CVSS 9.1 (critical): A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows an attacker to create arbitrary folders at any location on the…
CVE-2023-27958 — CVSS 9.1 (critical): The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur…
CVE-2022-46416 — CVSS 9.1 (critical): Parrot Bebop 4.7.1. allows remote attackers to prevent legitimate terminal connections by exhausting the DHCP IP address pool. To…
CVE-2019-15753 — CVSS 9.1 (critical): In OpenStack os-vif 1.15.x before 1.15.2, and 1.16.0, a hard-coded MAC aging time of 0 disables MAC learning in linuxbridge, forcing…
CVE-2023-43632 — CVSS 9.0 (critical): As noted in the “VTPM.md” file in the eve documentation, “VTPM is a server listening on port 8877 in EVE, exposing limited…
CVE-2026-97689: urllib3 is an HTTP client library for Python. From 1.10.3 until 2.8.0, the HTTPResponse.read_chunked and HTTPResponse.stream methods can…
CVE-2026-77403: RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Connection.openTune in connection.go accepts a server-advertised FrameMax…
CVE-2026-79921: amqp091-go is a Go AMQP 0.9.1 client. Before version 1.13.0, a compromised or malicious AMQP broker can force the client to allocate…
CVE-2024-35969 — CVSS 8.8 (high): In the Linux kernel, the following vulnerability has been resolved: ipv6: fix race condition between ipv6_get_ifaddr and ipv6_del_addr…
CVE-2023-5289 — CVSS 8.8 (high): Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.8.4.
CVE-2021-34735 — CVSS 8.8 (high): Multiple vulnerabilities in the Cisco ATA 190 Series Analog Telephone Adapter Software could allow an attacker to perform a command…
CVE-2020-24994 — CVSS 8.8 (high): Stack overflow in the parse_tag function in libass/ass_parse.c in libass before 0.15.0 allows remote attackers to cause a denial of service…
CVE-2019-5031 — CVSS 8.8 (high): An exploitable memory corruption vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader, version 9.4.1.16828. A…
CVE-2019-9291 — CVSS 8.8 (high): In Bluetooth, there is a possible remote code execution due to an improper memory allocation. This could lead to remote code execution in…
CVE-2019-10088 — CVSS 8.8 (high): A carefully crafted or corrupt zip file can cause an OOM in Apache Tika's RecursiveParserWrapper in versions 1.7-1.21. Users should upgrade…
CVE-2019-7582 — CVSS 8.8 (high): The readBytes function in util/read.c in libming through 0.4.8 allows remote attackers to have unspecified impact via a crafted swf file…
CVE-2019-7581 — CVSS 8.8 (high): The parseSWF_ACTIONRECORD function in util/parser.c in libming through 0.4.8 allows remote attackers to have unspecified impact via a…
CVE-2026-63772: Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift go bindings. This issue affects Apache Thrift: before…
CVE-2026-82458: Memory allocation with excessive size value, Allocation of resources without limits or throttling vulnerability in Apache Thrift Go…
CVE-2026-61373: Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java TSaslNonblockingServer. This issue affects Apache…
CVE-2026-91137: Improper validation of specified quantity in input, Allocation of resources without limits or throttling, Excessive Iteration vulnerability…
CVE-2026-63568: Allocation of resources without limits or throttling in the CMP/CRMF password-based MAC verifier (PKMacBuilder) in Legion of the Bouncy…
CVE-2026-61652: Zapros, a Python HTTP client, prior to version 0.14.0 is vulnerable to denial of service via memory exhaustion. The issue affects all…
CVE-2026-65654: github.com/temporalio/ringpop-go enforces configured LabelOptions limits when an application changes the local node's labels, but affected…
CVE-2026-75516: The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.34.0…
CVE-2026-19204: A client may send a WebSocket frame with an unknown opcode and a very large declared payload length, causing Jetty to attempt a large…