Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-770

MITRE ↗

CWE-770

31
CRITICAL
995
HIGH
1,035
MEDIUM
65
LOW
2,228 CVEs · Page 7/45
7.5
CVE-2026-54345

gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the Diameter AVP decoder computes

7.5
CVE-2026-54638

gotd/td is a T Telegram MTProto API client in Go. Prior to 0.145.1, proto.UnencryptedMessage.Decode in proto/unencrypted

7.5
CVE-2026-59899

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final,

7.5
CVE-2026-15975

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.8 before 19.0.5, 19.1 before 19.1.3, and 1

7.5
CVE-2026-67432

MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Tran

7.5
CVE-2026-67437

OliveTin gives access to predefined shell commands from a web interface. From 3000.0.0 until 3000.17.0, the service/inte

7.5
CVE-2026-11897

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service, caused by sen

7.5
CVE-2026-16308

IBM Enterprise Build of Quarkus 3.27.1 through 3.27.4.SP2, and 3.33.1 through 3.33.2.SP2 Quarkus REST could allow a remo

7.5
CVE-2026-12733

IBM DataPower Gateway could allow a remote attacker to cause a denial of service due to improper resource limitations.

7.5
CVE-2026-14539

An allocation of resources without limits vulnerability in the HTTP handler component of Google mcp-toolbox versions up

7.5
CVE-2026-67297

FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses

7.5
CVE-2026-54894

Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom c

7.5
CVE-2026-55733

Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom c

7.5
CVE-2026-55734

Allocation of Resources Without Limits or Throttling vulnerability in ueberauth guardian (Guardian.Permissions module) a

7.5
CVE-2026-13586

In Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS). This issue also a

7.5
CVE-2026-69152

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3

7.5
CVE-2026-66257

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to deni

7.5
CVE-2026-67465

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to deni

7.5
CVE-2026-67588

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to deni

7.5
CVE-2026-68060

A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential

7.5
CVE-2026-68074

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to deni

7.5
CVE-2026-67592

It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated att

7.5
CVE-2026-59675

When API audit logging is enabled, the middleware reads the entire HTTP request body into memory without enforcing a siz

7.5
CVE-2026-71314

Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an unauthenticated atta

7.5
CVE-2026-71321

Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, the internal island ren

7.5
CVE-2026-18649

A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements d

7.5
CVE-2026-54225

Apache CXF allows to control the maximum attachment size via the "attachment-max-size". Prior to Apache CXF 4.2.3 and 4.

7.5
CVE-2026-15972

Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 are vulnerable to an unauthenticated denial of servi

7.5
CVE-2026-52879

Klever-Go is the Go implementation of the Klever blockchain protocol. In versions 1.7.14 through 1.7.17, the direct-mess

7.5
CVE-2026-52880

Klever-Go is the Go implementation of the Klever blockchain protocol. Versions from 1.7.14 through 1.7.17 are vulnerable

7.5
CVE-2026-18618

A flaw was found in ml-metadata. The statically-linked gRPC stack in ml-metadata is outdated, making it vulnerable to kn

7.5
CVE-2026-72914

Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14, 4.6.4, and 4.7.0-be

7.5
CVE-2026-15561

A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an at

7.5
CVE-2026-54113

Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service o

7.5
CVE-2026-73089

Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to

7.5
CVE-2026-48802

python-engineio is a Python implementation of the Engine.IO realtime client and server. Prior to version 4.13.2, an atta

7.5
CVE-2026-48809

python-engineio is a Python implementation of the Engine.IO realtime client and server. Versions prior to 4.13.2 have tw

7.5
CVE-2026-48804

python-socketio is a Python implementation of the Socket.IO realtime client and server. The python-socketio server store

7.5
CVE-2025-41770

An unauthenticated denial-of-service vulnerability in the device's PLCnext Engineer communication interface allow an rem

7.5
CVE-2026-17271

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper validation of in

7.5
CVE-2026-71469

A flaw was found in search-v2-api. An unauthenticated attacker can exploit this by sending requests with unique random b

7.5
CVE-2026-73493

Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Prior to 0.23.18 and 1.0.0-M42,

7.5
CVE-2026-48702

Rekor is a software supply chain transparency log. Starting in version 0.3.0 and prior to version 1.5.2, the `Package.Un

7.5
CVE-2026-14456

Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destin

7.5
CVE-2026-70455

rsync 3.4.2 before 3.5.0 contains a denial of service vulnerability that allows a remote sender to exhaust system resour

7.5
CVE-2026-70464

rsync daemon 2.0.0 before 3.5.0 contains a denial of service vulnerability that allows unauthenticated remote attackers

7.5
CVE-2026-17199

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to unbounded resource alloca

7.5
CVE-2026-56853

When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they

7.5
CVE-2026-56859

Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.

7.5
CVE-2026-56862

Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has b

Frequently Asked Questions

What is CWE-770?

CWE-770 (CWE-770) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-770?

There are 2,515 CVE records associated with CWE-770 in our database. Of these, 31 are critical severity, 995 are high severity, and 1035 are medium severity.

How can I protect against CWE-770 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-770 using AI-powered security agents.

Detect CWE-770 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-770 vulnerabilities across your infrastructure.

Get Started