CWE-770

CWE-770 · 19 records · 4 with a public proof-of-concept

Records the NVD classes under CWE-770, highest CVSS first.

  1. HIGH 7.5CVE-2026-59675public PoC

    When API audit logging is enabled, the middleware reads the entire HTTP request body into memory without enforcing a size limit on login endpoints. Because the audit middleware is positioned earlier in the handler chain than Rancher's APIBodyLimitingHandler, t

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 7.5CVE-2026-67592

    It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are

    qpid protonj2

    AI risk analysis on Exploit-DB.ai →

  3. HIGH 7.5CVE-2026-68074

    A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes th

    qpid broker-j

    AI risk analysis on Exploit-DB.ai →

  4. HIGH 7.5CVE-2026-68060

    A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fix

    qpid broker-j

    AI risk analysis on Exploit-DB.ai →

  5. HIGH 7.5CVE-2026-67588

    A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the

    qpid protonj2

    AI risk analysis on Exploit-DB.ai →

  6. HIGH 7.5CVE-2026-67465

    A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes

    qpid proton-dotnet

    AI risk analysis on Exploit-DB.ai →

  7. HIGH 7.5CVE-2026-66257

    A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes th

    qpid proton-j

    AI risk analysis on Exploit-DB.ai →

  8. MEDIUM 6.5CVE-2026-16100

    A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error messages from failed account operations as Prometheus metric labels. Because these error messages can include user-supplied input like none

    build of keycloak

    AI risk analysis on Exploit-DB.ai →

  9. MEDIUM 6.5CVE-2026-68078

    It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users ar

    qpid broker-j

    AI risk analysis on Exploit-DB.ai →

  10. MEDIUM 6.5CVE-2026-68075

    An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the issue.

    qpid broker-j

    AI risk analysis on Exploit-DB.ai →

  11. MEDIUM 6.5CVE-2026-67591

    An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue.

    qpid protonj2

    AI risk analysis on Exploit-DB.ai →

  12. MEDIUM 6.5CVE-2026-67555

    It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users

    qpid proton-dotnet

    AI risk analysis on Exploit-DB.ai →

  13. MEDIUM 6.5CVE-2026-67553

    An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue.

    qpid proton-dotnet

    AI risk analysis on Exploit-DB.ai →

  14. MEDIUM 6.5CVE-2026-66277

    It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users ar

    qpid proton-j

    AI risk analysis on Exploit-DB.ai →

  15. MEDIUM 6.5CVE-2026-66275

    An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue.

    qpid proton-j

    AI risk analysis on Exploit-DB.ai →

  16. MEDIUM 6.5CVE-2026-67199

    Perspective 5.0.0 contains a denial of service vulnerability that allows remote attackers to block the server event loop indefinitely by submitting a crafted expression containing unbounded for or while loop constructs in a TableMakeViewReq message. Attackers

    AI risk analysis on Exploit-DB.ai →

  17. MEDIUM 4.3CVE-2026-55996public PoC

    A denial-of-service vulnerability was identified in multiple TLS listeners in Rancher. Both the cattle-cluster-agent component running in downstream clusters and the Rancher server itself use the dynamiclistener library to serve TLS traffic. Without an effecti

    AI risk analysis on Exploit-DB.ai →

  18. UNSCOREDCVE-2026-68494public PoC

    The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 (GHSA-72hv-8253-57qq, number length constraint bypass in the non-blocking parser) is incomplete. This record covers the remaining bypass. The earlier fix wired validateIntegerLength() into

    AI risk analysis on Exploit-DB.ai →

  19. UNSCOREDCVE-2026-18401public PoC

    The non-blocking (asynchronous) JSON parser in jackson-core does not enforce the maxNumberLength constraint defined in StreamReadConstraints (default: 1000 characters). An attacker able to submit JSON to an application that uses the async parser API can supply

    AI risk analysis on Exploit-DB.ai →