node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds
libp2p is a JavaScript Implementation of libp2p networking stack. Prior to 16.0.0, @libp2p/gossipsub defaultDecodeRpcLim
A denial-of-service vulnerability caused by unbounded resource allocation was discovered in the audit logging functional
Zeek before 8.0.9 contains an uncontrolled memory consumption vulnerability in the FTP analyzer that allows unauthentica
Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits or Throttling, Missing Authenticatio
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, the checkSheet(
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, the streaming w
RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, the RabbitMQ stream listener does not enforce the configur
Summary Cloudflare quiche was discovered to be vulnerable to memory resource exhaustion due to unbounded queuing of p
Pillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component
DBI::ProfileData versions before 1.651 for Perl do not limit the path index. The path index column of profile dump file
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service ove
Allocation of resources without limits or throttling in Windows HTTP.sys allows an unauthorized attacker to deny service
Allocation of resources without limits or throttling in HTTP/2 allows an unauthorized attacker to deny service over a ne
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service ove
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service ove
Pillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream.decode() in PIL/PdfParser.py calls zlib
pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and expon
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a netw
A vulnerability was found in libsoup's WebSocket frame parsing implementation. The library fails to validate length rule
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a netw
Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service o
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a netw
Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser
When an HTTP/2 profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource
A vulnerability was identified in the Feast Feature Server's `/ws/chat` endpoint that allows remote attackers to establi
Loki queries with large limits can cause large memory allocations which can impact the availability of the service, depe
h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 6b5370d, h2o is vulnerable to a Deni
h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 9265bdd, there is an HTTP/2 state am
Datadog .NET Tracer is a client library for Datadog APM for .NET applications. Prior to 3.43.0, Datadog tracing librarie
websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.1, draft versions of the WebSocket pro
websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.1, when websocket-driver is used to im
Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2
Datadog dd-trace-py is the Datadog Python APM client. Prior to 4.8.2, Datadog tracing libraries that implement W3C bagga
dd-trace is the Datadog APM client for Node.js. Prior to 5.100.0, W3C baggage propagation in packages/dd-trace/src/bagga
Datadog dd-trace-go is a Go client library for Datadog application performance monitoring, profiling, and security monit
Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the Mailpit SMTP server has a Server.M
Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2
Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface
A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runawa
brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the
Missing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path o
Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. Starting in version 0.1.0 and
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings. This issue affects A
Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings. This issue affects A
Improper Handling of Exceptional Conditions vulnerability in Erlang OTP erts (epmd) allows an unauthenticated remote att
Allocation of resources without limits in Erlang/OTP public_key certificate path validation allows a remote unauthentica
Pterodactyl is a free, open-source game server management panel. From 1.7.0 until 1.13.0, the authentication rate limite
gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the sFlow ExtendedGatewayFlow dec
Frequently Asked Questions
What is CWE-770?
CWE-770 (CWE-770) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-770?
There are 2,515 CVE records associated with CWE-770 in our database. Of these, 31 are critical severity, 995 are high severity, and 1035 are medium severity.
How can I protect against CWE-770 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-770 using AI-powered security agents.
Detect CWE-770 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-770 vulnerabilities across your infrastructure.
Get Started