CVE-2026-12733
IBM DataPower Gateway could allow a remote attacker to cause a denial of service due to improper resource limitations.
CVSS
7.5
High
EPSS
—
KEV
—
Exploit Today
0
0-100
Published: Jul 30, 2026 · Last modified: Jul 30, 2026 · CWE-770
Not enough EPSS history yet.
IBM DataPower Gateway could allow a remote attacker to cause a denial of service due to improper resource limitations.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-554976.5 MED—
——0Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the built-in thumbnail and avatar image decoders limit compressed file size but do not limit decoded pixel dimensions, allowing an authenticated user to submit a small PNG, JPEG, or GIF that triggers an unbounded allocation and terminates the Cloudreve process through fatal out-of-memory behavior. This issue is fixed in version 4.17.0.13hCVE-2026-14539——
——0An allocation of resources without limits vulnerability in the HTTP handler component of Google mcp-toolbox versions up to and including 1.4.0 allows an unauthenticated attacker to cause a denial of service (DoS). The /mcp endpoint handler reads incoming payloads directly into system memory using an unrestricted buffer loop (io.ReadAll) without applying defensive constraints such as http.MaxBytesReader or pre-read Content-Length enforcement. By submitting a single, massive HTTP request body, an attacker can linearly consume available host memory until the runtime process is terminated by an Out-Of-Memory (OOM) error.15hCVE-2026-163087.5 HIG—
——0IBM Enterprise Build of Quarkus 3.27.1 through 3.27.4.SP2, and 3.33.1 through 3.33.2.SP2 Quarkus REST could allow a remote attacker to cause a denial of service due to unbounded accumulation of multipart MIME part-header bytes.1dCVE-2026-118977.5 HIG—
——0IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.22hCVE-2026-183625.9 MED28.4%
——9The IRIS web application in version 2.4.26 and possibly others does not protect its user authentication against brute-force attacks.1dCVE-2026-169715.9 MED24.2%
——7The IRIS web application in version 2.4.26 and possibly others does not protect its MFA validation against brute-force attacks.1d