What is CWE-770?
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
CWE-770 is a base-level weakness in MITRE’s Common Weakness Enumeration, with a MITRE likelihood of exploit of High. Applicable platforms: Language: Not Language-Specific; Technology: Not Technology-Specific.
Source: MITRE CWE (CWE-770 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.
Consequences
- Availability — DoS: Resource Consumption (CPU), DoS: Resource Consumption (Memory), DoS: Resource Consumption (Other). When allocating resources without limits, an attacker could prevent other systems, applications, or processes from accessing the same type of resource. It can be easy for an attacker to consume many resources by rapidly making many requests or causing larger resources to be used than is needed.
Source: MITRE CWE, common consequences.
How CWE-770 is exploited in the wild
Threadlinqs maps 27 CVEs to CWE-770, published between 2025-10-15 and 2026-10-01. 1 is listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild. By CVSS v3 severity the set splits into 1 critical, 16 high, 5 medium, 1 low. The highest EPSS score in the set is 41.4% (CVE-2025-53521), the modelled probability of exploitation in the next 30 days. 21 tracked threats reference CWE-770 directly or through a CVE it covers; the most recent is “WatchGuard Fireware OS Critical Code Injection Vulnerability in BOVPN over TLS Client (CVE-2026-86131)” (2026-09-30). Affected products concentrate in moos-ivp (3), golang.org/x/crypto (2), h2o (2), among 22 vendors in total.
Vulnerabilities (CVEs)
All 27 CVEs mapped to CWE-770, CISA KEV first, then by CVSS score.
- CVE-2025-53521 — CISA KEV · CVSS 9.8 critical · EPSS 41.4% · published 2025-10-15
- CVE-2026-11622 — CVSS 7.5 high · EPSS 0.5% · published 2026-07-22
- CVE-2026-72914 — CVSS 7.5 high · EPSS 0.4% · published 2026-08-10
- CVE-2026-94624 — CVSS 7.5 high · EPSS 0.4% · published 2026-09-21
- CVE-2026-71321 — CVSS 7.5 high · EPSS 0.4% · published 2026-08-05
- CVE-2026-85449 — CVSS 7.5 high · EPSS 0.3% · published 2026-09-03
- CVE-2026-103761 — CVSS 7.5 high · EPSS 0.3% · published 2026-10-01
- CVE-2026-85447 — CVSS 7.5 high · EPSS 0.3% · published 2026-09-03
- CVE-2026-85448 — CVSS 7.5 high · EPSS 0.3% · published 2026-09-03
- CVE-2026-85450 — CVSS 7.5 high · EPSS 0.3% · published 2026-09-03
- CVE-2026-54638 — CVSS 7.5 high · EPSS 0.3% · published 2026-07-28
- CVE-2026-9675 — CVSS 7.5 high · EPSS 0.2% · published 2026-06-17
- CVE-2026-56855 — CVSS 7.5 high · EPSS 0.1% · published 2026-09-02
- CVE-2026-78662 — CVSS 7.5 high · EPSS 0.1% · published 2026-09-02
- CVE-2026-103042 — CVSS 7.5 high · published 2026-09-29
- CVE-2026-12151 — CVSS 7.5 high · published 2026-06-17
- CVE-2026-44453 — CVSS 7.5 high · published 2026-07-16
- CVE-2026-41899 — CVSS 6.5 medium · EPSS 0.3% · published 2026-07-06
- CVE-2026-18170 — CVSS 6.5 medium · EPSS 0.1% · published 2026-09-22
- CVE-2026-55078 — CVSS 6.5 medium · published 2026-07-07
- CVE-2026-44433 — CVSS 5.3 medium · published 2026-07-16
- CVE-2026-55205 — CVSS 5.3 medium · published 2026-06-18
- CVE-2026-61465 — CVSS 3.3 low · published 2026-07-11
- CVE-2026-82753 — EPSS 0.4% · published 2026-09-07
- CVE-2026-77337 — EPSS 0.3% · published 2026-08-24
- CVE-2026-86104 — EPSS 0.3% · published 2026-09-29
- CVE-2026-73500 — published 2026-08-12
Affected vendors
- moos-ivp — 3 CVEs
- golang.org/x/crypto — 2 CVEs
- h2o — 2 CVEs
- undici — 2 CVEs
- F5 — 1 CVE
- IBM — 1 CVE
- ISC — 1 CVE
- ImageMagick — 1 CVE
- ModelTC — 1 CVE
- WatchGuard — 1 CVE
- ash-project — 1 CVE
- cakephp — 1 CVE
Threat activity
21 tracked threats cite CWE-770:
- WatchGuard Fireware OS Critical Code Injection Vulnerability in BOVPN over TLS Client (CVE-2026-86131)CRITICAL
- F5 BIG-IP DNS Denial of Service via BIND DNSSEC Random Subdomain Attack (CVE-2026-11622)HIGH
- Condé Nast Data Breach: 32.8 Million User Records Offered for Sale Following WIRED LeakHIGH
- OWASP GenAI LLM Top 10 2026 — Community-Driven Security Guidance for AI ApplicationsMEDIUM
- GitLab Patches 13 Security Flaws (incl. CVE-2026-6267, CVE-2026-12436) Enabling Data Exposure, CI/CD Tampering, and DoSHIGH
- Vibe-Coded Applications Riddled With Exploitable Security Flaws — Theori Xint.io Study Finds 434 Issues Across AI-Generated CodebasesMEDIUM
- OpenSSL Silently Patches "HollowByte" Memory-Exhaustion DoS VulnerabilityMEDIUM
- OpenSSL "HollowByte" DoS Vulnerability — Memory Exhaustion via Malformed ClientHello (11-Byte Trigger)MEDIUM
- HollowByte: OpenSSL Pre-Authentication TLS DoS Flaw Bloats Server Memory With 11-Byte PayloadMEDIUM
- OpenSSL "HollowByte" TLS Handshake Memory-Amplification DoS (No CVE Assigned)MEDIUM
- Pro-Iran Hacktivist Ecosystem Uses Telegram to Coordinate DDoS, Hack-and-Leak, and Credential-Theft Campaigns (Handala, 313 Team, Cyber Fattah, Dark Storm, Keymous+, and Affiliated Personas)MEDIUM
- CVE-2026-55407: Unbounded Heap Allocation DoS in Anthropic's Buffa Rust Protobuf Library (decode_unknown_field)
- QNAP QSA-26-10: Multiple Injection and Memory-Safety Vulnerabilities in QTS, QuTS hero, QuTS cloud, QVP, and File Station (CVE-2025-66273, CVE-2026-26240, and 12 others)HIGH
- Node.js June 2026 Security Release — 12 Vulnerabilities Across 22.x/24.x/26.x Including Two High-Severity TLS Authentication Bypass and WebCrypto DoS Flaws (CVE-2026-48618, CVE-2026-48933)HIGH
- Dashlane Device-Registration API 2FA OTP Brute-Force Campaign — Encrypted Vaults of <20 Personal-Plan Accounts Exfiltrated (May–June 2026)HIGH
- HTTP/2 Bomb — Remote DoS via HPACK Indexed-Reference Compression Bomb + Zero-Window Flow-Control Hold Affecting nginx, Apache httpd, IIS, Envoy & Cloudflare Pingora (CVE-2026-49975, Public PoC)HIGH
- Multi-Stage Linux Intrusion via End-of-Life F5 BIG-IP and Unpatched Confluence — SSH Foothold to NTLM Relay (CVE-2025-33073, CVE-2025-53521)HIGH
- Kali365 PhaaS — Telegram-Distributed Microsoft 365 Device-Code Phishing with OAuth Token Theft & MFA Bypass (FBI PSA I-052126-PSA)HIGH
- F5 BIG-IP APM Unauthenticated Remote Code Execution via Stack Buffer Overflow (CVE-2025-53521) — CISA KEV Active Exploitation by Chinese Nation-State ActorCRITICAL
- CVE-2025-53521: F5 BIG-IP APM Unauthenticated Remote Code Execution via Stack-based Buffer OverflowCRITICAL
- CVE-2025-53521: F5 BIG-IP APM Unauthenticated Remote Code Execution via apmd Process — Active Exploitation by UNC5221 (BRICKSTORM)CRITICAL
Mitigations
- Requirements: Clearly specify the minimum and maximum expectations for capabilities, and dictate which behaviors are acceptable when resource allocation reaches limits.
- Architecture and Design: Limit the amount of resources that are accessible to unprivileged users. Set per-user limits for resources. Allow the system administrator to define these limits. Be careful to avoid CWE-410.
- Architecture and Design: Design throttling mechanisms into the system architecture. The best protection is to limit the amount of resources that an unauthorized user can cause to be expended. A strong authentication and access control model will help prevent such attacks from occurring in the first place, and it will help the administrator to identify who is committing the abuse. The login application should be protected against DoS attacks as much as possible. Limiting the database access, perhaps by caching result sets, can help minimize the resources expended. To further limit the potential for a DoS attack, consider tracking the rate of requests received from users and blocking requests that exceed a defined…
- Implementation / Input Validation: Assume all input is malicious. Use an "accept known good" input validation strategy, i.e., use a list of acceptable inputs that strictly conform to specifications. Reject any input that does not strictly conform to specifications, or transform it into something that does. When performing input validation, consider all potentially relevant properties, including length, type of input, the full range of acceptable values, missing or extra inputs, syntax, consistency across related fields, and conformance to business rules. As an example of business rule logic, "boat" may be syntactically valid because it only contains alphanumeric characters, but it is not valid if the input is only expected…
- Architecture and Design: For any security checks that are performed on the client side, ensure that these checks are duplicated on the server side, in order to avoid CWE-602. Attackers can bypass the client-side checks by modifying values after the checks have been performed, or by changing the client to remove the client-side checks entirely. Then, these modified values would be submitted to the server.
- Architecture and Design: Mitigation of resource exhaustion attacks requires that the target system either: recognizes the attack and denies that user further access for a given amount of time, typically by using increasing time delays uniformly throttles all requests in order to make it more difficult to consume resources more quickly than they can again be freed. The first of these solutions is an issue in itself though, since it may allow attackers to prevent the use of the system by a particular valid user. If the attacker impersonates the valid user, they may be able to prevent the user from accessing the server in question. The second solution can be difficult to effectively institute -- and even when properly…
- Architecture and Design: Ensure that protocols have specific limits of scale placed on them.
- Architecture and Design, Implementation: If the program must fail, ensure that it fails gracefully (fails closed). There may be a temptation to simply let the program fail poorly in cases such as low memory conditions, but an attacker may be able to assert control before the software has fully exited. Alternately, an uncontrolled failure could cause cascading problems with other downstream components; for example, the program could send a signal to a downstream process so the process immediately knows that a problem has occurred and has a better chance of recovery. Ensure that all failures in resource allocation place the system into a safe posture.
- Operation, Architecture and Design / Resource Limitation: Use quotas or other resource-limiting settings provided by the operating system or environment. For example, when managing system resources in POSIX, setrlimit() can be used to set limits for certain types of resources, and getrlimit() can determine how many resources are available. However, these functions are not available on all operating systems. When the current levels get close to the maximum that is defined for the application (see CWE-770), then limit the allocation of further resources to privileged users; alternately, begin releasing resources for less-privileged users. While this mitigation may protect the system from attack, it will not necessarily stop attackers from adversely…
Source: MITRE CWE, potential mitigations.
Detection methods (MITRE CWE)
- Manual Static Analysis: Manual static analysis can be useful for finding this weakness, but it might not achieve desired code coverage within limited time constraints. If denial-of-service is not considered a significant risk, or if there is strong emphasis on consequences such as code execution, then manual analysis may not focus on this weakness at all.
- Fuzzing (effectiveness: Opportunistic): While fuzzing is typically geared toward finding low-level implementation bugs, it can inadvertently find uncontrolled resource allocation problems. This can occur when the fuzzer generates a large number of test cases but does not restart the targeted product in between test cases. If an individual test case produces a crash, but it does not do so reliably, then an inability to limit resource allocation may be the cause. When the allocation is directly affected by numeric inputs, then fuzzing…
- Automated Dynamic Analysis: Certain automated dynamic analysis techniques may be effective in producing side effects of uncontrolled resource allocation problems, especially with resources such as processes, memory, and connections. The technique may involve generating a large number of requests to the product within a short time frame. Manual analysis is likely required to interpret the results.
- Automated Static Analysis: Specialized configuration or tuning may be required to train automated tools to recognize this weakness. Automated static analysis typically has limited utility in recognizing unlimited allocation problems, except for the missing release of program-independent system resources such as files, sockets, and processes, or unchecked arguments to memory. For system resources, automated static analysis may be able to detect circumstances in which resources are not released after they have expired, or…
Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.