CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,369 vulnerabilities with CWE-400
CVE-2026-55446 HIGH
Langflow: Unauthenticated DoS through multipart form boundary file upload
CVSS 7.5
CVE-2026-56248 HIGH
Capgo - Unauthenticated Denial-of-Service via audit_logs RLS Policy
CVSS 7.5
CVE-2026-49461 MEDIUM
pypdf: Possible large memory usage for form XObjects during text extraction
CVSS 5.5
CVE-2026-53539 HIGH
Python-Multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of service
CVSS 7.5
CVE-2026-50171 MEDIUM
Angular: Denial of Service (DoS) via OOM in Number Formatting (digitsInfo)
CVSS 6.1
CVE-2026-42127 HIGH
Grafana pre-auth DoS through arbitrarily large input to public dashboard query handler
CVSS 7.5
CVE-2026-9320 MEDIUM
IBM WebSphere Application Server and Liberty - Memory-Consumption Denial of Service
CVSS 5.9
CVE-2026-9071 HIGH
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by Uncontrolled Resource Consumption
CVSS 7.5
CVE-2026-54268 HIGH
Angular: Denial of Service (DoS) via OOM in Date Formatting (formatDate)
CVSS 7.5
CVE-2026-9375 HIGH
Decompression Bomb Bypass via Negative max_length in Streaming API in urllib3
CVSS 7.5
CVE-2026-49293 HIGH
CPU exhaustion via O(n^2) BigInt construction on radix-prefixed integer literals
CVSS 7.5
CVE-2026-27878 MEDIUM
Tempo TraceQL query with exemplar hint could result in unbounded memory usage
CVSS 6.5
CVE-2026-48937 MEDIUM
Node - Uncontrolled Resource Consumption
CVSS 5.3
CVE-2026-45357 HIGH
LiquidJS: Memory and render limit bypass via unbounded width padding in `date` filter (strftime)
CVSS 7.5
CVE-2026-44645 MEDIUM
LiquidJS has a renderLimit DoS guard bypass via empty `{% for %}` body
CVSS 6.5
CVE-2026-50196 HIGH
Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch
CVSS 7.5
CVE-2026-48990 MEDIUM
joserfc: b64=false RFC7797 JWS payloads bypass JWSRegistry payload-size limits during deserialization
CVSS 5.3
CVE-2026-48988 MEDIUM
markdown-it: Quadratic complexity DoS in smartquotes rule via replaceAt string operations
CVSS 5.3
CVE-2026-9675 HIGH
undici WebSocket client vulnerable to denial of service via cumulative fragment bypass
CVSS 7.5
CVE-2026-12151 HIGH
undici WebSocket client vulnerable to denial of service via fragment count bypass
CVSS 7.5
CVE-2026-48779 HIGH
ws: Memory exhaustion DoS from tiny fragments and data chunks
CVSS 7.5
CVE-2026-28575 MEDIUM
Google Android - Denial of Service
CVSS 5.5
CVE-2026-0064 MEDIUM
Google Android - Denial of Service
CVSS 5.5
CVE-2026-46914 HIGH
Oracle Solaris - Denial of Service
CVSS 7.1
CVE-2026-46910 CRITICAL
Oracle Corporation JD Edwards EnterpriseOne Tools < 9.2.26.2 - Denial of Service
CVSS 9.1
Details
Vulnerabilities 3,369
Exploit Likelihood High