Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2026-73635
Allocation of resources without limits or throttling vulnerability in Apache Struts. When no fixed locale is configured, the locale used for localize…
Struts
Fix unknown
HIGH 7.5
CVE-2026-54225
Apache CXF allows to control the maximum attachment size via the "attachment-max-size". Prior to Apache CXF 4.2.3 and 4.1.8 and 3.6.12, there was no …
Cxf
3.6.12 / 4.1.8+
MEDIUM 6.5
CVE-2026-68078
It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive reso…
Qpid Broker J
10.1.0+
MEDIUM 6.5
CVE-2026-68075
An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service.
This issue affects Apache …
Qpid Broker J
10.1.0+
HIGH 7.5
CVE-2026-67592
It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive reso…
Qpid Protonj2
1.2.0+
MEDIUM 6.5
CVE-2026-67555
It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive reso…
Qpid Proton Dotnet
1.1.0+
MEDIUM 6.5
CVE-2026-67553
An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service.
This issue affects Apache …
Qpid Proton Dotnet
1.1.0+
MEDIUM 6.5
CVE-2026-67591
An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service.
This issue affects Apache …
Qpid Protonj2
1.2.0+
MEDIUM 6.5
CVE-2026-66277
It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive reso…
Qpid Proton J
0.35.0+
MEDIUM 6.5
CVE-2026-66275
An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service.
This issue affects Apache …
Qpid Proton J
0.35.0+
HIGH 7.5
CVE-2026-67465
A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service.
This issue af…
Qpid Proton Dotnet
1.1.0+
HIGH 7.5
CVE-2026-67588
A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service.
This issue af…
Qpid Protonj2
1.2.0+
HIGH 7.5
CVE-2026-68060
A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service.
This iss…
Qpid Broker J
10.1.0+
HIGH 7.5
CVE-2026-68074
A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service.
This issue af…
Qpid Broker J
10.1.0+
HIGH 7.5
CVE-2026-66257
A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service.
This issue af…
Qpid Proton J
0.35.0+
HIGH 7.5
CVE-2026-58389
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings.
This issue affects Apache Thrift: before 0.24.0.
…
Thrift
0.24.0+
HIGH 7.5
CVE-2026-55968
Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Node.js bindings.
This issue…
Thrift
0.24.0+
HIGH 7.5
CVE-2026-45112
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings.
This issue affects Apache Thrift: from 0.19.0 bef…
Thrift
0.24.0+
HIGH 7.5
CVE-2026-54428
Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earl…
Httpcomponents Core
after 5.4.2
HIGH 7.5
CVE-2026-49361
Apache Fluss versions prior to 0.9.1 configure the Netty LengthFieldBasedFrameDecoder with Integer.MAX_VALUE as the maximum frame length, allowing un…
Fluss
0.9.1+
HIGH 7.5
CVE-2026-41284
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.2…
Tomcat
9.0.118 / 10.1.55+
MEDIUM 5.3
CVE-2025-69233
Due to multiple time-of-check time-of-use race conditions in the resource count check and increment logic, as well as missing validations, users of t…
Cloudstack
4.20.3.0 / 4.22.0.1+
HIGH 7.3
CVE-2026-29168
Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's mod_md via OCSP response data.
This issue affects Apache…
HTTP Server
2.4.67+
HIGH 7.5
CVE-2026-42440
OOM Denial of Service via Unbounded Array Allocation in Apache OpenNLP AbstractModelReader
Versions Affected:
before 1.9.5
before 2.5.9
before 3…
Opennlp
2.5.9+
HIGH 7.5
CVE-2026-39304
Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ.
ActiveMQ NIO SSL transports do…
Activemq
5.19.4 / 6.2.4+
HIGH 7.5
CVE-2025-48976EPSS 68%
Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload.
This issue affects …
Commons Fileupload
1.6+
HIGH 7.5
CVE-2025-48988EPSS 57%
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7…
Tomcat
9.0.106 / 10.1.42+
HIGH 7.5
CVE-2024-37358
Similarly to CVE-2024-34055, Apache James is vulnerable to denial of service through the abuse of IMAP literals from both authenticated and unauthent…
James Server
3.7.6 / 3.8.2+
HIGH 7.5
CVE-2024-38286
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0…
Tomcat
9.0.90 / 10.1.25+
HIGH 7.5
CVE-2024-27316EPSS 91%
HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client do…
HTTP Server
2.4.59+