← Back
CWE-770

2,032 CVEs • Abstraction: Base • Likelihood of Exploit: High

Allocation of Resources Without Limits or Throttling

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.

JSON object

Loading...

CVEs (2,032)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sonicwall
49Nsa 2650 Firmware
Nsa 2700 FirmwareNsa 3650 Firmware+46 more
Jun 17, 2026
Apr 27, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability in SonicOS CFS (Content filtering service) returns a large 403 forbidden HTTP response message to the source address when users try to access prohibited resource this allows an attacker to cause HTTP Deni...Show more
A vulnerability in SonicOS CFS (Content filtering service) returns a large 403 forbidden HTTP response message to the source address when users try to access prohibited resource this allows an attacker to cause HTTP Denial of Service (DoS) attackShow less
1Zammad
1Zammad
Jun 17, 2026
Apr 27, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A lack of rate limiting in the 'forgot password' feature of Zammad v5.1.0 allows attackers to send an excessive amount of reset requests for a legitimate user, leading to a possible Denial of Service (DoS) via a large am...Show more
A lack of rate limiting in the 'forgot password' feature of Zammad v5.1.0 allows attackers to send an excessive amount of reset requests for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.Show less
1F Secure
1Atlant
Jun 17, 2026
Apr 25, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the fsicapd component used in certain F-Secure products while scanning larger packages/fuzzed files consume too much memory eventually can...Show more
A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the fsicapd component used in certain F-Secure products while scanning larger packages/fuzzed files consume too much memory eventually can crash the scanning engine. The exploit can be triggered remotely by an attacker.Show less
1Fisglobal
1Gt.m
Jun 17, 2026
Apr 15, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can control the size of a memset that occurs in calls to util_format in sr_unix/util_output.c.
1Cisco
1Sd Wan Vedge Router
Jun 17, 2026
Apr 15, 2022
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
A vulnerability in the NETCONF process of Cisco SD-WAN vEdge Routers could allow an authenticated, local attacker to cause an affected device to run out of memory, resulting in a denial of service (DoS) condition. This v...Show more
A vulnerability in the NETCONF process of Cisco SD-WAN vEdge Routers could allow an authenticated, local attacker to cause an affected device to run out of memory, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient memory management when an affected device receives large amounts of traffic. An attacker could exploit this vulnerability by sending malicious traffic to an affected device. A successful exploit could allow the attacker to cause the device to crash, resulting in a DoS condition.Show less
1Cisco
1Aironet Access Point Software
Jun 17, 2026
Apr 15, 2022
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
A vulnerability in IP ingress packet processing of the Cisco Embedded Wireless Controller with Catalyst Access Points Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, c...Show more
A vulnerability in IP ingress packet processing of the Cisco Embedded Wireless Controller with Catalyst Access Points Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, causing a denial of service (DoS) condition. The device may experience a performance degradation in traffic processing or high CPU usage prior to the unexpected reload. This vulnerability is due to improper rate limiting of IP packets to the management interface. An attacker could exploit this vulnerability by sending a steady stream of IP traffic at a high rate to the management interface of the affected device. A successful exploit could allow the attacker to cause the device to reload.Show less
1Mattermost
1Mattermost Server
Jun 17, 2026
Apr 13, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The image proxy component in Mattermost version 6.4.1 and earlier allocates memory for multiple copies of a proxied image, which allows an authenticated attacker to crash the server via links to very large image files.
1Mattermost
1Playbooks
Jun 17, 2026
Apr 13, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Mattermost Playbooks plugin v1.24.0 and earlier fails to properly check the limit on the number of webhooks, which allows authenticated and authorized users to create a specifically drafted Playbook which could trigger a...Show more
Mattermost Playbooks plugin v1.24.0 and earlier fails to properly check the limit on the number of webhooks, which allows authenticated and authorized users to create a specifically drafted Playbook which could trigger a large amount of webhook requests leading to Denial of Service.Show less
1Waycrate
1Swhkd
Jun 17, 2026
Apr 7, 2022
N/A· v4
5.3 MEDIUM· v3
4.0 MEDIUM· v2
SWHKD 1.1.5 allows unsafe parsing via the -c option. An information leak might occur but there is a simple denial of service (memory exhaustion) upon an attempt to parse a large or infinite file (such as a block or chara...Show more
SWHKD 1.1.5 allows unsafe parsing via the -c option. An information leak might occur but there is a simple denial of service (memory exhaustion) upon an attempt to parse a large or infinite file (such as a block or character device).Show less
1Gitlab
1Gitlab
Jun 17, 2026
Apr 4, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A lack of appropriate timeouts in GitLab Pages included in GitLab CE/EE all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows an attacker to cause unlimited resource consumption.
1Vmware
1Spring Framework
Jun 17, 2026
Apr 1, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial of service condition.
1Ibm
1App Connect Enterprise Certified Container
Jun 17, 2026
Apr 1, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
IBM App Connect Enterprise Certified Container Dashboard UI (IBM App Connect Enterprise Certified Container 1.5, 2.0, 2.1, 3.0, and 3.1) may be vulnerable to denial of service due to excessive rate limiting.
1Totolink
2A720r Firmware
Ex300 V2 Firmware
Jun 17, 2026
Mar 31, 2022
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
totolink EX300_v2, ver V4.0.3c.140_B20210429 and A720R ,ver V4.1.5cu.470_B20200911 have an issue which causes uncontrolled resource consumption.
1Weka
1Interest Security Scanner
Nov 21, 2024
Mar 28, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability has been found in WEKA INTEREST Security Scanner up to 1.8 and classified as problematic. This vulnerability affects unknown code of the component Portscan. The manipulation with an unknown input leads to...Show more
A vulnerability has been found in WEKA INTEREST Security Scanner up to 1.8 and classified as problematic. This vulnerability affects unknown code of the component Portscan. The manipulation with an unknown input leads to denial of service. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainerShow less
1Nvidia
1Federated Learning Application Runtime Environment
Jun 17, 2026
Mar 17, 2022
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
NVIDIA FLARE contains a vulnerability in the admin interface, where an un-authorized attacker can cause Allocation of Resources Without Limits or Throttling, which may lead to cause system unavailable.
1Moodle
1Moodle
Jun 17, 2026
Mar 11, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A denial-of-service risk was identified in the draft files area, due to it not respecting user file upload limits. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier unsupported version...Show more
A denial-of-service risk was identified in the draft files area, due to it not respecting user file upload limits. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier unsupported versions are affected.Show less
1Nextcloud
1Nextcloud Server
Jun 17, 2026
Mar 9, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Nextcloud server is an open source, self hosted cloud style services platform. In affected versions an attacker can cause a denial of service by uploading specially crafted files which will cause the server to allocate t...Show more
Nextcloud server is an open source, self hosted cloud style services platform. In affected versions an attacker can cause a denial of service by uploading specially crafted files which will cause the server to allocate too much memory / CPU. It is recommended that the Nextcloud Server is upgraded to 21.0.8 , 22.2.4 or 23.0.1. Users unable to upgrade should disable preview generation with the `'enable_previews'` config flag.Show less
2Apache
Netapp
2Active Iq Unified Manager
Poi
Jun 17, 2026
Mar 4, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A shortcoming in the HMEF package of poi-scratchpad (Apache POI) allows an attacker to cause an Out of Memory exception. This package is used to read TNEF files (Microsoft Outlook and Microsoft Exchange Server). If an ap...Show more
A shortcoming in the HMEF package of poi-scratchpad (Apache POI) allows an attacker to cause an Out of Memory exception. This package is used to read TNEF files (Microsoft Outlook and Microsoft Exchange Server). If an application uses poi-scratchpad to parse TNEF files and the application allows untrusted users to supply them, then a carefully crafted file can cause an Out of Memory exception. This issue affects poi-scratchpad version 5.2.0 and prior versions. Users are recommended to upgrade to poi-scratchpad 5.2.1.Show less
4Debian
FedoraprojectOracle+1 more
5Debian Linux
FedoraHttp Server+2 more
Jun 17, 2026
Mar 3, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 22.2.0, Twisted SSH client and server implement is able to accept an infinite amount of data for the peer's SSH version iden...Show more
Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 22.2.0, Twisted SSH client and server implement is able to accept an infinite amount of data for the peer's SSH version identifier. This ends up with a buffer using all the available memory. The attach is a simple as `nc -rv localhost 22 < /dev/zero`. A patch is available in version 22.2.0. There are currently no known workarounds.Show less
1Hashicorp
1Nomad
Jun 17, 2026
Feb 28, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
HashiCorp Nomad and Nomad Enterprise 1.0.17, 1.1.11, and 1.2.5 allow invalid HCL for the jobs parse endpoint, which may cause excessive CPU usage. Fixed in 1.0.18, 1.1.12, and 1.2.6.