Skip to main content

CWE archive

CWE-770 CVEs

Programmatic archive

2,042 CVEs tagged with CWE-77029 Critical, 915 High, 1,021 Medium, 77 Low, 0 Unrated.

CVE-2026-7768

Published May 4, 2026

@fastify/accepts-serializer cached serializer-selection results keyed by the request Accept header without a size limit or eviction policy. A remote unauthenticated client could s…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-42236

Published May 4, 2026

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the MCP OAuth client registration endpoint accepted unauthenticated requests an…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-42154

Published May 4, 2026

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared…

CVSS 7.5 · High
evidence mentions
34
Buzz score
48.0
Vendor/product tagsBeta · best-effort

CVE-2026-42440

Published May 4, 2026

OOM Denial of Service via Unbounded Array Allocation in Apache OpenNLP AbstractModelReader  Versions Affected:  before 1.9.5 before 2.5.9 before 3.0.0-M3  Description: The A…

CVSS 7.5 · High
evidence mentions
5
Buzz score
32.4
Vendor/product tagsBeta · best-effort

CVE-2025-70071

Published May 4, 2026

An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXParser.cpp, ParseVectorDataArray()

CVSS 5.9 · Medium
evidence mentions
4
Buzz score
29.1

CVE-2025-70069

Published May 4, 2026

An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXConverter.cpp and ConvertMeshMultiMaterial() method

CVSS 7.5 · High
evidence mentions
4
Buzz score
29.1

CVE-2026-6948

Published May 4, 2026

Velociraptor versions prior to 0.76.4 contain a resource exhaustion vulnerability in the server's agent control channel. This allows a compromised or rogue Velociraptor client…

CVSS 4.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-42788

Published May 1, 2026

Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated memory exhaustion via oversized HTTP/2 frames. 'Elixir.Bandit.HTTP2.Fr…

CVSS 6.9 · Medium
evidence mentions
4
Buzz score
27.6

CVE-2026-42786

Published May 1, 2026

Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denial of service via memory exhaustion. The fragment reassembl…

CVSS 8.7 · High
evidence mentions
4
Buzz score
27.6

CVE-2026-39804

Published May 1, 2026

Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denial of service via memory exhaustion when WebSocket permessag…

CVSS 8.2 · High
evidence mentions
4
Buzz score
27.6

CVE-2026-43507

Published May 1, 2026

An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5. A Denial of Service can occur via memory exhaustion caused by XML parsing resource amplifi…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2025-36122

Published Apr 30, 2026

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user to cause a denial of service u…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-51846

Published Apr 30, 2026

CryptPad 2025.3.1 allows unbounded WebSocket frame flood. A remote, unauthenticated attacker can significantly degrade or deny service for all users of a CryptPad instance. Fixed…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2026-42198

Published Apr 29, 2026

pgjdbc is an open source postgresql JDBC Driver. From version 42.2.0 to before version 42.7.11, pgjdbc is vulnerable to a client-side denial of service during SCRAM-SHA-256 authen…

CVSS 7.5 · High
evidence mentions
9
Buzz score
36.0
Vendor/product tagsBeta · best-effort

CVE-2026-42420

Published Apr 28, 2026

OpenClaw before 2026.4.8 contains improper input validation in base64 decode paths that allocate memory before enforcing decoded-size limits. Attackers can exploit multiple code p…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-41408

Published Apr 28, 2026

OpenClaw before 2026.3.31 contains a resource exhaustion vulnerability in media downloads that bypasses core safety limits for file size, count, and cleanup operations. Attackers…

CVSS 2.3 · Low
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-41400

Published Apr 28, 2026

OpenClaw before 2026.3.31 contains an incomplete fix for CVE-2026-32062 where the voice-call component parses large WebSocket frames before start validation. Remote attackers can…

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-41399

Published Apr 28, 2026

OpenClaw before 2026.3.28 accepts unbounded concurrent unauthenticated WebSocket upgrades without pre-authentication budget allocation. Unauthenticated network attackers can exhau…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-32688

Published Apr 27, 2026

Allocation of Resources Without Limits or Throttling vulnerability in elixir-plug plug_cowboy allows unauthenticated remote denial of service via atom table exhaustion. Plug.Cowb…

CVSS 8.7 · High
evidence mentions
4
Buzz score
27.6
Vendor/product tagsBeta · best-effort

CVE-2026-42039

Published Apr 24, 2026

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, toFormData recursively walks nested objects with no depth limit, so a deeply nested v…

CVSS 6.9 · Medium
evidence mentions
41
Buzz score
43.0
Vendor/product tagsBeta · best-effort

CVE-2026-42036

Published Apr 24, 2026

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when responseType: 'stream' is used, Axios returns the response stream without enforc…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-42034

Published Apr 24, 2026

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, for stream request bodies, maxBodyLength is bypassed when maxRedirects is set to 0 (n…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-21728

Published Apr 24, 2026

Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy. Mitigation can be done…

CVSS 7.5 · High
evidence mentions
9
Buzz score
36.0
Vendor/product tagsBeta · best-effort

CVE-2026-41324

Published Apr 24, 2026

basic-ftp is an FTP client for Node.js. Versions prior to 5.3.0 are vulnerable to denial of service through unbounded memory growth while processing directory listings from a remo…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-41309

Published Apr 24, 2026

Open Source Social Network (OSSN) is open-source social networking software developed in PHP. Versions prior to 9.0 are vulnerable to resource exhaustion. An attacker can upload a…

CVSS 8.2 · High
evidence mentions
3
Buzz score
18.9
Showing 301-325 of 2,042 CVEsPage 13 of 82