CWE-400
High likelihoodUncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
3,094 vulnerabilities with CWE-400
CVE-2026-32588
MEDIUM
Apache Cassandra: Authenticated DoS via ALTER ROLE Password Hashing
CVSS 6.5
CVE-2026-35441
MEDIUM
Directus Affected by GraphQL Alias Amplification Denial-of-Service Due to Missing Query Cost/Complexity Limits
CVSS 6.5
CVE-2026-0049
MEDIUM
Android - Denial of Service via LocalImageResolver Header Decoding
CVSS 6.2
CVE-2026-34148
HIGH
Fedify affected by resource exhaustion caused by unbounded redirect following during remote key/document resolution
CVSS 7.5
CVE-2026-26477
MEDIUM
DokuWiki 2025-05-14b - Denial of Service via media_upload_xhr() Function
CVSS 4.3
CVE-2026-34827
HIGH
Rack: Algorithmic-Complexity DoS in Rack::Multipart::Parser
CVSS 7.5
CVE-2026-34593
HIGH
Ash Framework: Ash.Type.Module.cast_input/2 atom exhaustion via unchecked Module.concat allows BEAM VM crash
CVSS 7.5
CVE-2026-34829
HIGH
Rack: Denial of Service via Unbounded Multipart File Upload Without Content-Length
CVSS 7.5
CVE-2026-34826
MEDIUM
Rack: Unbounded Range Count in get_byte_ranges Enables DoS
CVSS 5.3
CVE-2026-34230
MEDIUM
Rack: Quadratic complexity in Rack::Utils.select_best_encoding via wildcard Accept-Encoding header
CVSS 5.3
CVE-2026-31935
HIGH
Suricata http2: unbounded resource consumption
CVSS 7.5
CVE-2026-5316
MEDIUM
Nothings stb stb_vorbis.c setup_free allocation of resources
CVSS 4.3
CVE-2026-22815
HIGH
AIOHTTP: Uncapped memory usage possible through aiohttp allowing unlimited trailer headers
CVSS 7.5
CVE-2026-34445
HIGH
ONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings.
CVSS 8.6
CVE-2026-34404
HIGH
Nuxt OG Image vulnerable to DoS via image generation
CVSS 7.5
CVE-2026-34043
MEDIUM
Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects
CVSS 5.9
CVE-2026-33750
MEDIUM
brace-expansion: Zero-step sequence causes process hang and memory exhaustion
CVSS 6.5
CVE-2026-28375
MEDIUM
Grafana Testdata datasource can issue unbounded memory allocations
CVSS 6.5
CVE-2026-27879
MEDIUM
Query resampling can cause unbounded memory allocations
CVSS 6.5
CVE-2026-27859
MEDIUM
OX Dovecot Pro < 2.4.0, < 3.0.2, < 3.1.0 - Uncontrolled Resource Consumption via RFC 2231 MIME Parameters
CVSS 5.3
CVE-2026-27858
HIGH
OX Dovecot Pro < 2.3.0, < 3.1.0, < 2.4.0 - Unauthenticated Denial of Service via Managesieve Memory Allocation
CVSS 7.5
CVE-2026-27857
MEDIUM
OX Dovecot Pro < 2.3.0 - Denial of Service via NOOP Command Memory Exhaustion
CVSS 4.3
CVE-2026-33623
MEDIUM
PinchTab: OS Command Injection via Profile Name in Windows Cleanup Routine Enables Arbitrary Command Execution
CVSS 6.7
CVE-2026-33541
MEDIUM
TSPortal's Uncontrolled User Creation via Validation Side Effects Leads to Potential Denial of Service
CVSS 6.5
CVE-2026-33375
MEDIUM
Grafana MSSQL Data Source Plugin: Restriction Bypass Leading to OOM DoS
CVSS 6.5
Details
Vulnerabilities
3,094
Exploit Likelihood
High