CWE-770


Allocation of Resources Without Limits or Throttling

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.


We have discovered 2,275,819 live websites that are affected by CWE-770.

Contact us to get more info









CVEs

  • Count - 61



Website Distribution by Country

Number of websites using CWE-770
United States645,401 websites



Germany236,324 websites
Taiwan114,589 websites
France113,634 websites
Netherlands89,971 websites
Russia85,879 websites
Japan77,066 websites
GB76,829 websites
Italy73,976 websites
Canada53,565 websites

Website Distribution by TLD

Number of websites using CWE-770
.com899,052 websites
.de143,475 websites
.org111,213 websites
.net78,854 websites
.ru73,362 websites
.nl71,375 websites
.it60,912 websites
.co.uk47,270 websites
.fr40,685 websites
.pl36,389 websites

Newest CVEs

List of the most recent CVEs that are part of CWE-770
DiscoveredCVEDescriptionWebsites
Apr, 2026CVE-2026-21388 Unbounded Request Body Read in MS Teams Plugin {{/lifecycle}} Webhook Endpoint1
Apr, 2026CVE-2026-33034 Potential denial-of-service vulnerability in ASGI requests via memory upload limit bypass67
Apr, 2026CVE-2026-34513 AIOHTTP: Denial of Service (DoS) via Unbounded DNS Cache in TCPConnector181
Apr, 2026CVE-2026-34516 AIOHTTP: Multipart Header Size Bypass181
Apr, 2026CVE-2026-34517 AIOHTTP: Late size enforcement for non-file multipart fields causes memory DoS181
Mar, 2026CVE-2026-29772 Astro: Memory exhaustion DoS due to missing request body size limit in Server Islands19,491
Mar, 2026CVE-2026-24458 DoS attack via login attempts with multi-megabyte passwords150
Mar, 2026CVE-2026-29795 stellar-xdr: `StringM::from_str` bypasses max length validation5
Mar, 2026CVE-2026-27601 Underscore.js has unlimited recursion in _.flatten and _.isEqual, potential for DoS attack674,069
Feb, 2026CVE-2026-25224 Fastify Vulnerable to DoS via Unbounded Memory Allocation in sendWebStream1
List of the most common CVEs that are part of CWE-770
DiscoveredCVEDescriptionWebsites
Jun, 2022CVE-2022-29404 Denial of service in mod_lua r:parsebody1,334,135
Apr, 2024CVE-2024-27316 Apache HTTP Server: HTTP/2 DoS by memory exhaustion on endless continuation frames884,338
Mar, 2026CVE-2026-27601 Underscore.js has unlimited recursion in _.flatten and _.isEqual, potential for DoS attack674,069
Jul, 2020CVE-2020-8203 Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.27,492
Mar, 2026CVE-2026-29772 Astro: Memory exhaustion DoS due to missing request body size limit in Server Islands19,491
Jun, 2025CVE-2025-48988 Apache Tomcat: FileUpload large number of parts with headers DoS7,033
Nov, 2024CVE-2024-38286 Apache Tomcat: Denial of Service3,524
Feb, 2026CVE-2026-24133 jsPDF Affected by Denial of Service (DoS) via Unvalidated BMP Dimensions in BMPDecoder3,424
Sep, 2025CVE-2025-58754 Axios is vulnerable to DoS attack through lack of data size check2,347
Jan, 2026CVE-2025-68659 Discourse has DoS vulnerability in username change endpoint1,979

Websites affected by CWE-770

Top websites that are affected by CWE-770. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.com Singapore***
*********.de Germany***
*****.net Canada***
*************.***.****.****.************.net United States***
*****.***********.com Canada***
*****.com United States***
****.fr France***
****.com United States***
*****.com United States***
**.cn China***
See full domain list