React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Co
Dell BSAFE SSL-J contains an allocation of resources without limits or throttling vulnerability. An unauthenticated remo
Cloudburst Network provides network components used within Cloudburst projects. A vulnerability in versions prior to `1.
Uncontrolled Resource Consumption vulnerability in ninenines gun (gun_http module) allows a malicious server to exhaust
In Micrometer, it is possible for a user to provide specially crafted gRPC requests that may cause a denial-of-service (
In Micrometer, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (
Spring HATEOAS maintains an unbounded static cache of StringLinkRelation instances keyed on attacker-supplied strings.
Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the
Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network.
Spring Data's internal property-lookup cache accepts and permanently retains attacker-supplied strings as cache keys, al
Russh is a Rust SSH client & server library. Prior to version 0.60.3, CryptoVec used unchecked capacity growth, unchecke
Russh is a Rust SSH client & server library. From version 0.34.0 to before version 0.61.1, when SSH compression is enabl
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-
vLLM versions 0.8.0 and later are vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded f
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.10 before 18.10.8, 18.11 before 18.11.5, a
Axios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.x did not enforce co
Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to
Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina
Netty is a network application framework for development of protocol servers and clients. In versions of netty-transport
Netty is a network application framework for development of protocol servers and clients. Starting in version 4.2.0.Fina
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina
ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, f
Impact: The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but d
Impact: The undici WebSocket client enforces maxPayloadSize per-frame but does not enforce the cumulative size of fragme
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.35.11, 1.36.7
The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attacke
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, no limit was present on
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, if an attacker sends la
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, it is possible to bypas
Starlette is a lightweight ASGI framework/toolkit. From 0.4.1 until 1.3.1, request.form() accepts max_fields and max_par
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, when MessagePack-CSharp decompresses
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, UnsafeBlitFormatterBase<T>.Deserializ
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePack-CSharp's multi-dimensiona
Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inheri
An issue in the time_t_to_dt component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Ser
Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. From 1.0.0 unti
Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, Mistune is vulnerable to a CPU exhaustio
A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2Gi
Net::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustion via an uncapped peer-wire message-length
A vulnerability in the InstallShield file format parser of ClamAV could allow an unauthenticated, remote attacker to cau
Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 an
An unauthenticated remote attacker can exhaust server memory via the FindServers Discovery Service in open62541. The ser
In Eclipse Parsson published Maven Central artifacts before version 1.1.8, the JSON parser did not enforce a default max
An unauthenticated remote attacker can exhaust server memory via the GetEndpoints Discovery Service in open62541. The en
Eclipse Wakaama before snapshot/2026-05-26 contains an unbounded memory allocation vulnerability in the CoAP Block1 hand
By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound on memory allocation
A memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote a
Allocation of Resources Without Limits or Throttling vulnerability in phoenixframework phoenix (Phoenix.Socket module) a
App::Ack versions before 3.10.0 for Perl allow memory exhaustion via an unbounded context value in a project .ackrc. ac
Frequently Asked Questions
What is CWE-770?
CWE-770 (CWE-770) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-770?
There are 2,515 CVE records associated with CWE-770 in our database. Of these, 31 are critical severity, 995 are high severity, and 1035 are medium severity.
How can I protect against CWE-770 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-770 using AI-powered security agents.
Detect CWE-770 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-770 vulnerabilities across your infrastructure.
Get Started