Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-789'

View all threats tagged with 'cwe-789'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-789

Threats Tagged 'cwe-789'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-46602: CWE-789: Memory Allocation with Excessive Size Value in golang.org/x/image golang.org/x/image/tiffCVE-2026-46602
0

A vulnerability in the golang.org/x/image/tiff package allows unbounded memory consumption due to the TIFF decoder not limiting the size of tiles in tiled images. This can be triggered by a malicious or corrupt TIFF image containing an excessively large tile. The issue affects versions prior to 0.43.0.

Join the discussion
CVE-2026-54448: CWE-770: Allocation of Resources Without Limits or Throttling in aquasecurity trivyCVE-2026-54448
0

Trivy is a security scanner. Prior to 0.71.0, when Trivy scans a Helm chart archive (.tgz), its custom tar unpacker reads each entry with io.ReadAll(tr) and no size limit. An attacker who can place a malicious .tgz file in the scanned path can craft a small compressed archive that decompresses to gigabytes, causing the Trivy process to be killed by the OS OOM killer. This vulnerability is fixed in 0.71.0.

Join the discussion
Red Hat Security Advisory: mod_http2 security updateCVE-2026-49975
0

A security vulnerability (CVE-2026-49975) affects the mod_http2 Apache httpd module used in Red Hat Enterprise Linux 10. The flaw allows a remote attacker to cause a denial of service (DoS) via a compression bomb and Slowloris-style attack against HTTP/2 connections. Red Hat has issued an important security update to address this issue in mod_http2 version 2.0.29-4.el10_2.1. The vulnerability impacts HTTP/2 implementations on httpd 2.4 servers using libnghttp2. The update is available for multiple architectures and extended support versions of Red Hat Enterprise Linux 10.

Join the discussion
CVE-2026-44967: CWE-789: Memory Allocation with Excessive Size Value in open-telemetry opentelemetry-cppCVE-2026-44967
0

A memory allocation vulnerability exists in open-telemetry opentelemetry-cpp prior to version 1.27.0. The OTLP HTTP exporters read the full HTTP response into memory without limiting the size, which can lead to memory exhaustion if the collector endpoint is attacker-controlled or if a network attacker can intercept the connection. This issue is fixed in version 1.27.0.

Join the discussion
CVE-2026-47734: CWE-400: Uncontrolled Resource Consumption in jelmer dulwichCVE-2026-47734
0

Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.1.0 and prior to version 1.2.5, a client with push access could push a tiny crafted thin pack (~174 bytes) whose delta header declares a huge dest_size. When dulwich ingested it via add_thin_pack / apply_delta, it would allocate hundreds of MB of memory based on that attacker-controlled size, with no relationship to the actual bytes received. Operators running a Dulwich-based Git server that exposes git-receive-pack (i.e. accepts pushes) - for example via dulwich.server functionality, the HTTP smart server, or anything built on ReceivePackHandler - are impacted. The issue is patched in 1.2.5. add_thin_pack now accepts a max_input_size keyword (bytes; 0/None = unlimited, matching git's semantics), and ReceivePackHandler reads receive.maxInputSize from the repository config and passes it through. Wire reads are counted and a PackInputTooLarge exception is raised once the cap is exceeded - equivalent to git index-pack --max-input-size. Users should upgrade to Dulwich 1.2.5 or later and set receive.maxInputSize in their server's repository config to a sane bound for their environment. On unpatched versions, receive.maxInputSize has no effect, so it cannot be used as a workaround. Until upgrading, operators should restrict dulwich-receive-pack (push) access to trusted, authenticated clients only, or disable it entirely on servers that only need to serve fetches and/or run the server under an OS-level memory limit (e.g. ulimit, cgroups/MemoryMax, or a container memory limit) so a malicious push is killed rather than taking down the host.

Join the discussion
CVE-2026-10142: CWE-789 Memory Allocation with Excessive Size Value in Dana Powers kafka-pythonCVE-2026-10142
0

kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in the protocol parser that allows a malicious broker or machine-in-the-middle attacker to exhaust memory or hang connections by sending a crafted 4-byte frame length value without bounds validation. Attackers can send a specially crafted frame length through the receive_bytes() function to trigger either a multi-gigabyte memory allocation or an uncaught ValueError that leaves the connection in a broken state, causing requests to hang and consumers to stop heartbeating until restart.

Join the discussion
CVE-2024-43484: CWE-407: Inefficient Algorithmic Complexity in Microsoft .NET 6.0CVE-2024-43484
0

.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability

Join the discussion
CVE-2026-49975: CWE-789 Memory Allocation with Excessive Size Value in Apache Software Foundation Apache HTTP ServerCVE-2026-49975
0

Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67.

Join the discussion
CVE-2026-41178: CWE-789: Memory Allocation with Excessive Size Value in open-telemetry go.opentelemetry.io/otel/baggageCVE-2026-41178
0

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Versions 1.41.0 and 1.43.0 removed raw-length rejection and it causes `Parse` to process arbitrarily large/invalid baggage headers and log errors, enabling DoS via oversized inputs. Versions 1.42.0 and 1.44.0 fix the issue.

Join the discussion
CVE-2026-47319: CWE-789 Memory allocation with excessive size value in Samsung Open Source rlottieCVE-2026-47319
0

Memory allocation with excessive size value vulnerability in Samsung Open Source rlottie allows Excessive Allocation. This issue affects rlottie: before 0b4e308fa88c72cbb60cc8a2c1d2c2ad89b101dd.

Join the discussion

Showing 1 to 10 of 10 results

Filters:Tag: cwe-789
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses