Threats Tagged 'cwe-770'
View all threats tagged with 'cwe-770'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-770'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-67585: CWE-770 Allocation of Resources Without Limits or Throttling in DivvyPayHQ absinthe_federationCVE-2026-67585 0 A resource allocation vulnerability in DivvyPayHQ absinthe_federation allows unauthenticated remote attackers to exhaust the Erlang VM atom table by sending crafted _entities representation keys. This causes the node to abort, impacting availability without affecting data integrity or confidentiality. Recovery requires restarting the application. The issue affects absinthe_federation versions from 0.1.0 up to but not including 0.9.3. Join the discussion | GCVE Database | 08/07/2026, 16:42:22 UTC Added: 08/08/2026, 14:52:17 UTC |
CVE-2025-71411: CWE-770 in ATN-B1 CPDLCCVE-2025-71411 0 CVE-2025-71411 is a medium severity vulnerability in the ATN-B1 CPDLC system where broadcast control frames can be exploited remotely over radio frequency to disconnect multiple aircraft simultaneously. This disruption can cause delayed clearances and overload air traffic controllers. The vulnerability relates to improper handling of shared resources (CWE-770). No patch or official remediation guidance is currently available. Join the discussion | CVE Database V5 | 08/07/2026, 21:30:37 UTC Added: 08/08/2026, 12:51:35 UTC |
CVE-2025-71410: CWE-770 in ATN-B1 CPDLCCVE-2025-71410 0 CVE-2025-71410 is a vulnerability in the ATN-B1 CPDLC system where unnumbered disconnect and malformed Aviation Very High Frequency Link Control frames can terminate communication sessions. This disruption leads to loss of CPDLC functionality, forcing a fallback to voice communication and increasing controller workload. The attack can be executed remotely over radio frequency. Join the discussion | CVE Database V5 | 08/07/2026, 21:30:37 UTC Added: 08/08/2026, 12:51:35 UTC |
CVE-2026-52880: CWE-400: Uncontrolled Resource Consumption in klever-io klever-goCVE-2026-52880 0 Klever-Go is the Go implementation of the Klever blockchain protocol. Versions from 1.7.14 through 1.7.17 are vulnerable to a remotely triggerable denial of service. Both REST APIs are started with the Gin Engine.Run convenience method, which serves requests through Go's default HTTP server with no ReadHeaderTimeout, ReadTimeout, or MaxHeaderBytes configured. As a result, incoming connections that never complete their request headers are held open indefinitely. When a REST listener is reachable beyond localhost through the documented all-interface bind or a Docker port-publish deployment, a single unauthenticated client can open many slow-header connections and hold them open until server file descriptors are exhausted, preventing the API from accepting new connections. This renders the REST API unavailable to legitimate clients. This issue is fixed in version 1.7.18. Join the discussion | CVE Database V5 | 08/07/2026, 22:53:41 UTC Added: 08/07/2026, 22:56:58 UTC |
CVE-2026-52879: CWE-400: Uncontrolled Resource Consumption in klever-io klever-goCVE-2026-52879 0 Klever-Go is the Go implementation of the Klever blockchain protocol. In versions 1.7.14 through 1.7.17, the direct-message ingress handler spawns a new goroutine for every incoming direct message before the processor-level antiflood layer makes any admission decision, with no semaphore, throttler, or bound on the number of concurrent in-flight spawns. Because the antiflood check runs inside the spawned goroutine rather than before it, a single connected peer can open a direct-send stream and send a stream of well-formed messages to force unbounded goroutine creation, where each goroutine allocates its own stack and holds a message reference until processing completes, adding scheduler and garbage-collection pressure faster than the runtime can drain it. This lets one peer degrade the node's availability and its ability to process legitimate traffic, resulting in a remotely triggerable denial of service. The issue is fixed in 1.7.18. Join the discussion | CVE Database V5 | 08/07/2026, 22:36:53 UTC Added: 08/07/2026, 22:41:53 UTC |
CVE-2026-19015: CWE-770: Allocation of Resources Without Limits or Throttling in HashiCorp ConsulCVE-2026-19015 0 Consul Community Edition and Consul Enterprise 1.2.0 through 2.0.2 are vulnerable to an uncontrolled resource consumption issue in the Connect CA roots endpoint that may allow a remote caller to grow the agent's Connect CA roots cache without bound, defeating the operator's cache-disable configuration. This vulnerability, CVE-2026-19015, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3. Join the discussion | CVE Database V5 | 08/07/2026, 21:30:37 UTC Added: 08/07/2026, 19:42:01 UTC |
CVE-2026-19014: CWE-770: Allocation of Resources Without Limits or Throttling in HashiCorp ConsulCVE-2026-19014 0 Consul Community Edition and Consul Enterprise 1.17.0 through 2.0.2 are vulnerable to an uncontrolled resource consumption issue in the Connect authorization endpoint that may allow a caller to grow the agent's intention-match cache without bound, defeating the operator's cache-disable configuration. This vulnerability, CVE-2026-190124, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3. Join the discussion | CVE Database V5 | 08/07/2026, 21:30:37 UTC Added: 08/07/2026, 19:42:01 UTC |
CVE-2026-15972: CWE-770: Allocation of Resources Without Limits or Throttling in HashiCorp ConsulCVE-2026-15972 0 Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 are vulnerable to an unauthenticated denial of service through unbounded connection acceptance on the external gRPC listeners. A remote attacker may exhaust agent file descriptors, goroutines, and memory by opening many incomplete connections, potentially preventing legitimate clients from connecting. This vulnerability, CVE-2026-15972, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3. Join the discussion | CVE Database V5 | 08/07/2026, 21:30:37 UTC Added: 08/07/2026, 19:42:01 UTC |
CVE-2026-67585: CWE-770 Allocation of Resources Without Limits or Throttling in DivvyPayHQ absinthe_federationCVE-2026-67585 0 Allocation of Resources Without Limits or Throttling vulnerability in DivvyPayHQ absinthe_federation allows an unauthenticated remote attacker to abort the Erlang VM via crafted _entities representation keys. Every key of every object in the representations argument of the federation-mandated _entities field is converted with String.to_atom/1 by convert_key/2 in lib/absinthe/federation/schema/entities_field.ex. representations is typed as the open-ended _Any scalar, so its keys bypass schema coercion and the attacker names them freely. Atoms are never garbage collected and the BEAM atom table is hard-capped (about 1,048,576 entries by default), so one request carrying tens of thousands of unique keys creates that many permanent atoms and a handful of such requests exhausts the table and aborts the node. The impact is confined to availability: no data is read or altered, and recovery requires restarting the application. This issue affects absinthe_federation: from 0.1.0 before 0.9.3. Join the discussion | CVE Database V5 | 08/07/2026, 16:42:22 UTC Added: 08/07/2026, 16:56:50 UTC |
CVE-2026-42561: CWE-770: Allocation of Resources Without Limits or Throttling in Kludex python-multipartCVE-2026-42561 0 Red Hat Lightspeed in Satellite analyzes system health and configuration by applying predefined rules to a small set of local data, such as installed packages, running services, and configuration settings. When you install Red Hat Lightspeed in Satellite locally, you can generate Red Hat Lightspeed recommendations without sending system data to Red Hat services. Join the discussion | GCVE Database | 05/13/2026, 20:55:11 UTC Added: 08/07/2026, 05:56:40 UTC |
Showing 1 to 10 of 120 results