The product manages a group of objects or resources and performs a separate memory allocation for each object, but it does not properly limit the total amount of memory that is consumed by all of the combined objects.
Volume of CVEs assigned to CWE-1325 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-2511MEDIUM Issue summary: Some non-default TLS server configurations can cause unbounded
memory growth when processing TLSv1.3 sessions
Impact summary: An attacker may exploit certain server | Apr 8, 2024 | 5.9 | 49 | NO | NO |
CVE-2026-34183HIGH Issue summary: Remote peer may exhaust heap memory of the QUIC
server or client by flooding it with packets containing PATH_CHALLENGE
frames.
Impact summary: A malicious remote pe | Jun 9, 2026 | 7.5 | 36 | NO | NO |
CVE-2026-3201HIGH USB HID protocol dissector memory exhaustion in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service | Feb 25, 2026 | 7.5 | 28 | NO | NO |
CVE-2026-13056MEDIUM Using expressions that generate large arrays it is possible to craft a query that creates very large intermediate objects in memory, causing the server to crash with OOM error. | Jul 22, 2026 | 6.5 | 27 | NO | NO |
CVE-2023-3341HIGH The code that processes control channel messages sent to `named` calls certain functions recursively during packet parsing. Recursion depth is only limited by the maximum accepted | Sep 20, 2023 | 7.5 | 26 | NO | NO |
CVE-2026-8199MEDIUM An authenticated user can cause excess memory usage via bitwise match expression AST processing of $bitsAllSet, $bitsAnySet, $bitsAllClear, and $bitsAnyClear. This contributes to m | May 13, 2026 | 6.5 | 25 | NO | NO |
CVE-2026-6535MEDIUM Dissection engine zlib decompression crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service | Apr 30, 2026 | 5.5 | 25 | NO | NO |
CVE-2026-6533MEDIUM Dissection engine LZ77 decompression crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service | Apr 30, 2026 | 5.5 | 25 | NO | NO |
CVE-2021-43174HIGH NLnet Labs Routinator versions 0.9.0 up to and including 0.10.1, support the gzip transfer encoding when querying RRDP repositories. This encoding can be used by an RRDP repository | Nov 9, 2021 | 7.5 | 25 | NO | NO |
CVE-2026-6869MEDIUM WebSocket protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service | Apr 30, 2026 | 5.5 | 24 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.