Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify vstarting
Improper input handling in a system endpoint may allow attackers to overload resources, causing a denial of service.
Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.5, 4.4.12, and 4.3.18,
Discourse is an open source discussion platform. Versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0 have an app
zae-limiter is a rate limiting library using the token bucket algorithm. Prior to version 0.10.1, all rate limit buckets
Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to 2.2.4, the chunke
Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands wi
A vulnerability was identified in Nothings stb up to 1.22. The impacted element is the function setup_free of the file s
An issue in Dokuwiki v.2025-05-14b "Librarian" [56.2] allows a remote attacker to cause a denial of service via the medi
OpenClaw before 2026.3.31 contains a resource exhaustion vulnerability in media downloads that bypasses core safety limi
OpenClaw before 2026.4.8 contains improper input validation in base64 decode paths that allocate memory before enforcing
Incus is a system container and virtual machine manager. Prior to version 7.0.0, uploads of large amount of data by auth
An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomple
Using a densely populated chars mask and a large input string in the MongoDB aggregation operators $trim, $ltrim, and $r
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to limit the size of the request body o
Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation allows Excessi
Nanobot prior to version 0.2.1 contains a denial of service vulnerability in the Matrix channel media download handler t
Summarize before 0.17.0 contains a resource exhaustion vulnerability that allows remote attackers to cause disk exhausti
libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted sequence of H.265
Capgo before 12.128.2 contains a denial of service vulnerability in the POST /app/demo endpoint that allows authenticate
IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow an authenticated user to cause a temporary denial u
n8n before 2.28.0 (and before 1.123.58 on the 1.x branch) contains a disk space exhaustion vulnerability in the data-tab
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of service via a craft
Elgg before 7.0.0 does not check image dimensions to prevent denial of service via a large avatar upload.
Allocation of resources without limits or throttling vulnerability in BizimHesap Information Systems Industry and Trade
Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to bound the time and
A denial-of-service vulnerability was identified in multiple TLS listeners in Rancher. Both the cattle-cluster-agent com
Consul Community Edition and Consul Enterprise 1.17.0 through 2.0.2 are vulnerable to an uncontrolled resource consumpti
SAP Approuter does not enforce sufficient flow control in certain functionality. An attacker with low privileges could s
vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the /v1/completions/derender and /v1
ArcadeDB before 26.8.1 contains a denial of service vulnerability in the Cypher range() function that allows authenticat
A flaw was found in FreeIPA. A low-privilege authenticated user can exploit this vulnerability by submitting an oversize
stellar-xdr is a library and CLI containing types and functionality for working with Stellar XDR. Prior to version 25.0.
Varnish Enterprise before 6.0.16r12 allows a "workspace overflow" denial of service (daemon panic) for shared VCL. The h
A flaw was found in KubeVirt's downward metrics virtio-serial server. The server reads guest requests using textproto.Re
OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte
CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL
Fastify is a fast and low overhead web framework, for Node.js. Prior to version 5.7.3, a denial-of-service vulnerability
Mattermost Plugins versions <=2.3.1 fail to limit the request body size on the {{/lifecycle}} webhook endpoint which all
Mattermost Plugins versions <=2.1.3.0 fail to limit the request body size on the {{/changes}} webhook endpoint which all
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
ciguard is a static security auditor for CI/CD pipelines. From 0.6.0 to 0.8.1, both SCA HTTP clients (src/ciguard/analyz
sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive au
Impact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an i
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver
### Summary When `qs.parse` is called with `comma: true` and `throwOnLimitExceeded: true`, a comma-separated value un
IBM Jazz Reporting Service could allow an authenticated user on the host network to cause a denial of service using spec
A security vulnerability has been detected in GPAC up to 26.02.0. This affects the function sidx_box_read of the file sr
NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a denial-of-service vulnerability exists i
ImageMagick before 7.1.2-26 and 6.9.13-51 is missing a check for the allowed memory allocation limit in matrix-backed op
Frequently Asked Questions
What is CWE-770?
CWE-770 (CWE-770) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-770?
There are 2,515 CVE records associated with CWE-770 in our database. Of these, 31 are critical severity, 995 are high severity, and 1035 are medium severity.
How can I protect against CWE-770 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-770 using AI-powered security agents.
Detect CWE-770 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-770 vulnerabilities across your infrastructure.
Get Started