Vulnerability index

Browse CVEs

63 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Struts HIGH 7.5
CVE-2026-73635

Allocation of resources without limits or throttling vulnerability in Apache Struts. When no fixed locale is configured, the locale used for localize…

Fix unknown
Fix from $4,900 2026-08-15
Cxf HIGH 7.5
CVE-2026-54225

Apache CXF allows to control the maximum attachment size via the "attachment-max-size". Prior to Apache CXF 4.2.3 and 4.1.8 and 3.6.12, there was no …

Fix: 3.6.12 / 4.1.8+
Fix from $1,950 2026-08-06
Qpid Broker J MEDIUM 6.5
CVE-2026-68078

It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive reso…

Fix: 10.1.0+
Fix from $1,600 2026-08-05
Qpid Broker J MEDIUM 6.5
CVE-2026-68075

An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache …

Fix: 10.1.0+
Fix from $1,600 2026-08-05
Qpid Protonj2 HIGH 7.5
CVE-2026-67592

It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive reso…

Fix: 1.2.0+
Fix from $1,950 2026-08-05
Qpid Proton Dotnet MEDIUM 6.5
CVE-2026-67555

It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive reso…

Fix: 1.1.0+
Fix from $1,600 2026-08-05
Qpid Proton Dotnet MEDIUM 6.5
CVE-2026-67553

An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache …

Fix: 1.1.0+
Fix from $1,600 2026-08-05
Qpid Protonj2 MEDIUM 6.5
CVE-2026-67591

An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache …

Fix: 1.2.0+
Fix from $1,600 2026-08-05
Qpid Proton J MEDIUM 6.5
CVE-2026-66277

It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive reso…

Fix: 0.35.0+
Fix from $1,600 2026-08-05
Qpid Proton J MEDIUM 6.5
CVE-2026-66275

An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache …

Fix: 0.35.0+
Fix from $1,600 2026-08-05
Qpid Proton Dotnet HIGH 7.5
CVE-2026-67465

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue af…

Fix: 1.1.0+
Fix from $1,950 2026-08-05
Qpid Protonj2 HIGH 7.5
CVE-2026-67588

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue af…

Fix: 1.2.0+
Fix from $1,950 2026-08-05
Qpid Broker J HIGH 7.5
CVE-2026-68060

A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This iss…

Fix: 10.1.0+
Fix from $1,950 2026-08-05
Qpid Broker J HIGH 7.5
CVE-2026-68074

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue af…

Fix: 10.1.0+
Fix from $1,950 2026-08-05
Qpid Proton J HIGH 7.5
CVE-2026-66257

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue af…

Fix: 0.35.0+
Fix from $1,950 2026-08-05
Thrift HIGH 7.5
CVE-2026-58389

Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings. This issue affects Apache Thrift: before 0.24.0. …

Fix: 0.24.0+
Fix from $1,950 2026-07-27
Thrift HIGH 7.5
CVE-2026-55968

Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Node.js bindings. This issue…

Fix: 0.24.0+
Fix from $1,950 2026-07-27
Thrift HIGH 7.5
CVE-2026-45112

Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings. This issue affects Apache Thrift: from 0.19.0 bef…

Fix: 0.24.0+
Fix from $1,950 2026-07-27
Httpcomponents Core HIGH 7.5
CVE-2026-54428

Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earl…

Fix: after 5.4.2
Fix from $1,950 2026-07-01
Fluss HIGH 7.5
CVE-2026-49361

Apache Fluss versions prior to 0.9.1 configure the Netty LengthFieldBasedFrameDecoder with Integer.MAX_VALUE as the maximum frame length, allowing un…

Fix: 0.9.1+
Fix from $1,950 2026-06-01
Tomcat HIGH 7.5
CVE-2026-41284

Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.2…

Fix: 9.0.118 / 10.1.55+
Fix from $1,950 2026-05-12
Cloudstack MEDIUM 5.3
CVE-2025-69233

Due to multiple time-of-check time-of-use race conditions in the resource count check and increment logic, as well as missing validations, users of t…

Fix: 4.20.3.0 / 4.22.0.1+
Fix from $1,600 2026-05-08
HTTP Server HIGH 7.3
CVE-2026-29168

Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's  mod_md via OCSP response data. This issue affects Apache…

Fix: 2.4.67+
Fix from $1,950 2026-05-05
Opennlp HIGH 7.5
CVE-2026-42440

OOM Denial of Service via Unbounded Array Allocation in Apache OpenNLP AbstractModelReader  Versions Affected:  before 1.9.5 before 2.5.9 before 3…

Fix: 2.5.9+
Fix from $1,950 2026-05-04
Activemq HIGH 7.5
CVE-2026-39304

Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ. ActiveMQ NIO SSL transports do…

Fix: 5.19.4 / 6.2.4+
Fix from $1,950 2026-04-10
Commons Fileupload HIGH 7.5
CVE-2025-48976EPSS 68%

Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload. This issue affects …

Fix: 1.6+
Fix from $1,950 2025-06-16
Tomcat HIGH 7.5
CVE-2025-48988EPSS 57%

Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7…

Fix: 9.0.106 / 10.1.42+
Fix from $1,950 2025-06-16
James Server HIGH 7.5
CVE-2024-37358

Similarly to CVE-2024-34055, Apache James is vulnerable to denial of service through the abuse of IMAP literals from both authenticated and unauthent…

Fix: 3.7.6 / 3.8.2+
Fix from $1,950 2025-02-06
Tomcat HIGH 7.5
CVE-2024-38286

Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0…

Fix: 9.0.90 / 10.1.25+
Fix from $1,950 2024-11-07
HTTP Server HIGH 7.5
CVE-2024-27316EPSS 91%

HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client do…

Fix: 2.4.59+
Fix from $1,950 2024-04-04