Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-789

MITRE ↗

CWE-789

2
CRITICAL
70
HIGH
57
MEDIUM
3
LOW
144 CVEs · Page 2/3
7.5
CVE-2026-44453

h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 6b5370d, h2o is vulnerable to a Deni

7.5
CVE-2026-47667

CImg Library is a C++ library for image processing. Prior to version 4.0.0 in `_load_analyze()`, the header_size field i

7.5
CVE-2026-65315

Ollama (HEAD f0078ae) contains an uncontrolled memory allocation vulnerability in the GGUF metadata parser that allows r

7.5
CVE-2026-54890

Integer Underflow (Wrap or Wraparound) vulnerability in erlang otp erlang/otp (erts modules), erlang otp erts (erts modu

7.5
CVE-2026-54638

gotd/td is a T Telegram MTProto API client in Go. Prior to 0.145.1, proto.UnencryptedMessage.Decode in proto/unencrypted

7.5
CVE-2026-59646

In Bouncy Castle for Java before 1.85, DTLS handshake reassembler allocates buffer from unchecked 24-bit length. This is

7.5
CVE-2026-12852

In Bouncy Castle for Java before 1.85, MLS wire decoder allocates attacker-declared opaque length before bounds check.

7.5
CVE-2026-14682

In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This i

7.5
CVE-2026-66273

A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential

7.5
CVE-2026-67551

pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential d

7.5
CVE-2026-67589

A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential

7.5
CVE-2026-61485

** UNSUPPORTED WHEN ASSIGNED ** Memory Allocation with Excessive Size Value vulnerability in Apache Lucy. This issue af

7.5
CVE-2026-70377

imagecli's pipeline operation (Scale::apply in src/image_ops.rs) computes output width/height as (dimension as f32 * rat

7.5
CVE-2026-71314

Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an unauthenticated atta

7.5
CVE-2026-66733

Sonic 3 A.I.R. before commit 2492d18 contains an unbounded memory allocation vulnerability in ReceivedPacketCache::enque

7.5
CVE-2026-44630

Improper validation of length fields in the Apache IoTDB RPC service may allow a remote unauthenticated attacker to caus

7.5
CVE-2026-15567

A flaw was found in Wildfly. A remote unauthenticated attacker can trigger OutOfMemoryError as CSIv2Util's GSS token dec

7.5
CVE-2026-19566

Net::CIDR::Set versions before 0.23 for Perl allow memory exhaustion and malformed set ranges via unbounded IPv6 prefix

7.5
CVE-2026-46603

VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image

7.5
CVE-2026-75935

Uncontrolled memory allocation in the binary Ion stream cursor in Amazon ion-java before 1.12.0 might allow remote actor

7.5
CVE-2026-81692

openssl_encrypt (pip: openssl-encrypt) versions 1.4.8 and earlier fail to validate the 36-bit STREAMINFO total_samples f

7.5
CVE-2026-81693

openssl_encrypt before 1.4.9 fails to validate the total field from QR JSON payloads before materializing ranges. Attack

6.5
CVE-2025-2668

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 is vulnerable to a denial of service a

6.5
CVE-2026-25579

Navidrome is an open source web-based music collection server and streamer. Prior to version 0.60.0, authenticated users

6.5
CVE-2026-27204

Wasmtime is a runtime for WebAssembly. Prior to versions 24.0.6, 36.0.6, 4.0.04, 41.0.4, and 42.0.0, Wasmtime's implemen

6.5
CVE-2026-32941

Sliver is a command and control framework that uses a custom Wireguard netstack. Versions 1.7.3 and below contain a Remo

6.5
CVE-2026-35549

An issue was discovered in MariaDB Server before 11.4.10, 11.5.x through 11.8.x before 11.8.6, and 12.x before 12.2.2. I

6.5
CVE-2026-41312

pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior

6.5
CVE-2026-41314

pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior

6.5
CVE-2026-42946

A vulnerability exists in the ngx_http_scgi_module and ngx_http_uwsgi_module modules that may result in excessive memory

6.5
CVE-2026-54448

Trivy is a security scanner. Prior to 0.71.0, when Trivy scans a Helm chart archive (.tgz), its custom tar unpacker read

6.5
CVE-2026-58559

DoS vulnerability in the vibration service. Impact: Successful exploitation of this vulnerability may affect availabilit

6.5
CVE-2025-71395

SurrealDB versions before 2.2.2 contain a memory exhaustion vulnerability in the string::replace function that fails to

6.5
CVE-2026-59844

A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large leng

6.5
CVE-2026-69702

SnailJob 1.7.0 contains a denial of service vulnerability in the FuryUtil.deserialize helper that allows authenticated a

6.5
CVE-2026-72639

Elasticsearch does not enforce an upper bound on a user-supplied count accepted by a search highlighting option, and the

6.5
CVE-2026-72645

Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Alloc

6.5
CVE-2026-72656

Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query processing of Elasticsearch can lead to denial

6.5
CVE-2026-72678

Elasticsearch does not validate a size value taken from a user-supplied input before that value is used to reserve memor

6.5
CVE-2026-72687

A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single small request containing a forged

6.2
CVE-2026-32836

dr_libs dr_flac.h version 0.13.3 and earlier (fixed in commits fefced4, 4f5a4cd, and 663239a) contain an uncontrolled me

6.2
CVE-2018-25274

InfraRecorder 0.53 contains a denial of service vulnerability that allows local attackers to crash the application by im

6.2
CVE-2018-25279

jiNa OCR Image to Text 1.0 contains a denial of service vulnerability that allows local attackers to crash the applicati

6.2
CVE-2018-25295

ObserverIP Scan Tool 1.4.0.1 contains a denial of service vulnerability that allows local attackers to crash the applica

6.2
CVE-2018-25378

Notebook Pro 2.0 contains a denial of service vulnerability that allows local attackers to crash the application by supp

6.2
CVE-2026-17535

Velociraptor's NTFS parsing library mishandles several out of bound and memory exhaustion bugs which may be triggered by

6.1
CVE-2026-47319

Memory allocation with excessive size value vulnerability in Samsung Open Source rlottie allows Excessive Allocation. T

5.9
CVE-2025-66199

Issue summary: A TLS 1.3 connection using certificate compression can be forced to allocate a large buffer before decomp

5.9
CVE-2026-42348

OpenTelemetry.OpAmp.Client is the OpAMP client for OpenTelemetry .NET. Prior to 0.2.0-alpha.1, when receiving responses

5.9
CVE-2026-8485

Uncontrolled Memory Allocation vulnerability in Progress Software MOVEit Automation allows Excessive Allocation. This i

Frequently Asked Questions

What is CWE-789?

CWE-789 (CWE-789) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-789?

There are 145 CVE records associated with CWE-789 in our database. Of these, 2 are critical severity, 70 are high severity, and 57 are medium severity.

How can I protect against CWE-789 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-789 using AI-powered security agents.

Detect CWE-789 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-789 vulnerabilities across your infrastructure.

Get Started