← Back
CWE-770

2,032 CVEs • Abstraction: Base • Likelihood of Exploit: High

Allocation of Resources Without Limits or Throttling

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.

JSON object

Loading...

CVEs (2,032)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
5Debian
FedoraprojectNetapp+2 more
13Communications Brm Elastic Charging Engine
Communications Cloud Native Core Service Communication ProxyCommunications Design Studio+10 more
Jun 17, 2026
Apr 7, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte stream. An attacker could send a large ZlibEncoded byte stream to the Netty server, forcing the server...Show more
The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte stream. An attacker could send a large ZlibEncoded byte stream to the Netty server, forcing the server to allocate all of its free memory to a single decoder.Show less
2Fedoraproject
Kubernetes
2Fedora
Kubernetes
Jun 17, 2026
Mar 27, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The Kubernetes API server component in versions prior to 1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via successful API requests.
2Fedoraproject
Kubernetes
2Fedora
Kubernetes
Jun 17, 2026
Mar 27, 2020
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
The Kubelet component in versions 1.15.0-1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via the kubelet API, including the unauthenticated HTTP read-only API typica...Show more
The Kubelet component in versions 1.15.0-1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via the kubelet API, including the unauthenticated HTTP read-only API typically served on port 10255, and the authenticated HTTPS API typically served on port 10250.Show less
1Mikrotik
1Routeros
Jun 17, 2026
Mar 23, 2020
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
The SSH daemon on MikroTik routers through v6.44.3 could allow remote attackers to generate CPU activity, trigger refusal of new authorized connections, and cause a reboot via connect and write system calls, because of u...Show more
The SSH daemon on MikroTik routers through v6.44.3 could allow remote attackers to generate CPU activity, trigger refusal of new authorized connections, and cause a reboot via connect and write system calls, because of uncontrolled resource management.Show less
1Signotec
1Signopad Api/web
Jun 17, 2026
Mar 20, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in signotec signoPAD-API/Web (formerly Websocket Pad Server) before 3.1.1 on Windows. It is possible to perform a Denial of Service attack because the application doesn't limit the number of opene...Show more
An issue was discovered in signotec signoPAD-API/Web (formerly Websocket Pad Server) before 3.1.1 on Windows. It is possible to perform a Denial of Service attack because the application doesn't limit the number of opened WebSocket sockets. If a victim visits an attacker-controlled website, this vulnerability can be exploited.Show less
1Facebook
1Thrift
Jun 17, 2026
Mar 18, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory...Show more
Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2020.03.16.00.Show less
1Facebook
1Thrift
Jun 17, 2026
Mar 10, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
C++ Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory all...Show more
C++ Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2020.02.03.00.Show less
1Facebook
1Thrift
Jun 17, 2026
Mar 10, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Java Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory al...Show more
Java Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.12.09.00.Show less
3Cncf
DebianRedhat
3Debian Linux
EnvoyOpenshift Service Mesh
Jun 17, 2026
Mar 4, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
CNCF Envoy through 1.13.0 may consume excessive amounts of memory when proxying HTTP/1.1 requests or responses with many small (i.e. 1 byte) chunks.
1Qt
1Qt
Nov 21, 2024
Feb 28, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Qt through 5.14.1, the WebSocket implementation accepts up to 2GB for frames and 2GB for messages. Smaller limits cannot be configured. This makes it easier for attackers to cause a denial of service (memory consumpti...Show more
In Qt through 5.14.1, the WebSocket implementation accepts up to 2GB for frames and 2GB for messages. Smaller limits cannot be configured. This makes it easier for attackers to cause a denial of service (memory consumption).Show less
1Ibm
1Websphere Application Server
Jun 17, 2026
Jan 31, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consu...Show more
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume all available memory. IBM X-Force ID: 172125.Show less
1Hashicorp
1Consul
Jun 17, 2026
Jan 31, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
HashiCorp Consul and Consul Enterprise up to 1.6.2 HTTP/RPC services allowed unbounded resource usage, and were susceptible to unauthenticated denial of service. Fixed in 1.6.3.
1Hashicorp
1Nomad
Jun 17, 2026
Jan 31, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
HashiCorp Nomad and Nonad Enterprise up to 0.10.2 HTTP/RPC services allowed unbounded resource usage, and were susceptible to unauthenticated denial of service. Fixed in 0.10.3.
1Iktm
1Bearftp
Jun 17, 2026
Jan 29, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IKTeam BearFTP before 0.2.0 allows remote attackers to achieve denial of service via a large volume of connections to the PASV mode port.
1Codesys
15Control For Beaglebone
Control For Empc A/imx6Control For Iot2000+12 more
Jun 17, 2026
Jan 24, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
CODESYS Control V3, Gateway V3, and HMI V3 before 3.5.15.30 allow uncontrolled memory allocation which can result in a remote denial of service condition.
2Oracle
Vt
4Communications Services Gatekeeper
CryptacularWebcenter Sites+1 more
Jun 17, 2026
Jan 24, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
CiphertextHeader.java in Cryptacular 1.2.3, as used in Apereo CAS and other products, allows attackers to trigger excessive memory allocation during a decode operation, because the nonce array length associated with "new...Show more
CiphertextHeader.java in Cryptacular 1.2.3, as used in Apereo CAS and other products, allows attackers to trigger excessive memory allocation during a decode operation, because the nonce array length associated with "new byte" may depend on untrusted input within the header of encoded data.Show less
2Gnu
Opensuse
3Backports
LeapLibredwg
Jun 17, 2026
Jan 8, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
GNU LibreDWG 0.9.3.2564 has an attempted excessive memory allocation in read_sections_map in decode_r2007.c.
2Fedoraproject
Thekelleys
2Dnsmasq
Fedora
Jun 17, 2026
Jan 7, 2020
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
A vulnerability was found in dnsmasq before version 2.81, where the memory leak allows remote attackers to cause a denial of service (memory consumption) via vectors involving DHCP response creation.
1Matio Project
1Matio
Jun 17, 2026
Dec 27, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An attempted excessive memory allocation was discovered in Mat_VarRead5 in mat5.c in matio 1.5.17.
2Gnu
Opensuse
3Backports Sle
LeapLibredwg
Jun 17, 2026
Dec 27, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_LWPOLYLINE_private in dwg.spec.