CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,094 vulnerabilities with CWE-400
CVE-2026-32588 MEDIUM
Apache Cassandra: Authenticated DoS via ALTER ROLE Password Hashing
CVSS 6.5
CVE-2026-35441 MEDIUM
Directus Affected by GraphQL Alias Amplification Denial-of-Service Due to Missing Query Cost/Complexity Limits
CVSS 6.5
CVE-2026-0049 MEDIUM
Android - Denial of Service via LocalImageResolver Header Decoding
CVSS 6.2
CVE-2026-34148 HIGH
Fedify affected by resource exhaustion caused by unbounded redirect following during remote key/document resolution
CVSS 7.5
CVE-2026-26477 MEDIUM
DokuWiki 2025-05-14b - Denial of Service via media_upload_xhr() Function
CVSS 4.3
CVE-2026-34827 HIGH
Rack: Algorithmic-Complexity DoS in Rack::Multipart::Parser
CVSS 7.5
CVE-2026-34593 HIGH
Ash Framework: Ash.Type.Module.cast_input/2 atom exhaustion via unchecked Module.concat allows BEAM VM crash
CVSS 7.5
CVE-2026-34829 HIGH
Rack: Denial of Service via Unbounded Multipart File Upload Without Content-Length
CVSS 7.5
CVE-2026-34826 MEDIUM
Rack: Unbounded Range Count in get_byte_ranges Enables DoS
CVSS 5.3
CVE-2026-34230 MEDIUM
Rack: Quadratic complexity in Rack::Utils.select_best_encoding via wildcard Accept-Encoding header
CVSS 5.3
CVE-2026-31935 HIGH
Suricata http2: unbounded resource consumption
CVSS 7.5
CVE-2026-5316 MEDIUM
Nothings stb stb_vorbis.c setup_free allocation of resources
CVSS 4.3
CVE-2026-22815 HIGH
AIOHTTP: Uncapped memory usage possible through aiohttp allowing unlimited trailer headers
CVSS 7.5
CVE-2026-34445 HIGH
ONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings.
CVSS 8.6
CVE-2026-34404 HIGH
Nuxt OG Image vulnerable to DoS via image generation
CVSS 7.5
CVE-2026-34043 MEDIUM
Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects
CVSS 5.9
CVE-2026-33750 MEDIUM
brace-expansion: Zero-step sequence causes process hang and memory exhaustion
CVSS 6.5
CVE-2026-28375 MEDIUM
Grafana Testdata datasource can issue unbounded memory allocations
CVSS 6.5
CVE-2026-27879 MEDIUM
Query resampling can cause unbounded memory allocations
CVSS 6.5
CVE-2026-27859 MEDIUM
OX Dovecot Pro < 2.4.0, < 3.0.2, < 3.1.0 - Uncontrolled Resource Consumption via RFC 2231 MIME Parameters
CVSS 5.3
CVE-2026-27858 HIGH
OX Dovecot Pro < 2.3.0, < 3.1.0, < 2.4.0 - Unauthenticated Denial of Service via Managesieve Memory Allocation
CVSS 7.5
CVE-2026-27857 MEDIUM
OX Dovecot Pro < 2.3.0 - Denial of Service via NOOP Command Memory Exhaustion
CVSS 4.3
CVE-2026-33623 MEDIUM
PinchTab: OS Command Injection via Profile Name in Windows Cleanup Routine Enables Arbitrary Command Execution
CVSS 6.7
CVE-2026-33541 MEDIUM
TSPortal's Uncontrolled User Creation via Validation Side Effects Leads to Potential Denial of Service
CVSS 6.5
CVE-2026-33375 MEDIUM
Grafana MSSQL Data Source Plugin: Restriction Bypass Leading to OOM DoS
CVSS 6.5
Details
Vulnerabilities 3,094
Exploit Likelihood High