CWE-400
High likelihoodUncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
3,369 vulnerabilities with CWE-400
CVE-2026-55446
HIGH
Langflow: Unauthenticated DoS through multipart form boundary file upload
CVSS 7.5
CVE-2026-56248
HIGH
Capgo - Unauthenticated Denial-of-Service via audit_logs RLS Policy
CVSS 7.5
CVE-2026-49461
MEDIUM
pypdf: Possible large memory usage for form XObjects during text extraction
CVSS 5.5
CVE-2026-53539
HIGH
Python-Multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of service
CVSS 7.5
CVE-2026-50171
MEDIUM
Angular: Denial of Service (DoS) via OOM in Number Formatting (digitsInfo)
CVSS 6.1
CVE-2026-42127
HIGH
Grafana pre-auth DoS through arbitrarily large input to public dashboard query handler
CVSS 7.5
CVE-2026-9320
MEDIUM
IBM WebSphere Application Server and Liberty - Memory-Consumption Denial of Service
CVSS 5.9
CVE-2026-9071
HIGH
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by Uncontrolled Resource Consumption
CVSS 7.5
CVE-2026-54268
HIGH
Angular: Denial of Service (DoS) via OOM in Date Formatting (formatDate)
CVSS 7.5
CVE-2026-9375
HIGH
Decompression Bomb Bypass via Negative max_length in Streaming API in urllib3
CVSS 7.5
CVE-2026-49293
HIGH
CPU exhaustion via O(n^2) BigInt construction on radix-prefixed integer literals
CVSS 7.5
CVE-2026-27878
MEDIUM
Tempo TraceQL query with exemplar hint could result in unbounded memory usage
CVSS 6.5
CVE-2026-48937
MEDIUM
Node - Uncontrolled Resource Consumption
CVSS 5.3
CVE-2026-45357
HIGH
LiquidJS: Memory and render limit bypass via unbounded width padding in `date` filter (strftime)
CVSS 7.5
CVE-2026-44645
MEDIUM
LiquidJS has a renderLimit DoS guard bypass via empty `{% for %}` body
CVSS 6.5
CVE-2026-50196
HIGH
Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch
CVSS 7.5
CVE-2026-48990
MEDIUM
joserfc: b64=false RFC7797 JWS payloads bypass JWSRegistry payload-size limits during deserialization
CVSS 5.3
CVE-2026-48988
MEDIUM
markdown-it: Quadratic complexity DoS in smartquotes rule via replaceAt string operations
CVSS 5.3
CVE-2026-9675
HIGH
undici WebSocket client vulnerable to denial of service via cumulative fragment bypass
CVSS 7.5
CVE-2026-12151
HIGH
undici WebSocket client vulnerable to denial of service via fragment count bypass
CVSS 7.5
CVE-2026-48779
HIGH
ws: Memory exhaustion DoS from tiny fragments and data chunks
CVSS 7.5
CVE-2026-28575
MEDIUM
Google Android - Denial of Service
CVSS 5.5
CVE-2026-0064
MEDIUM
Google Android - Denial of Service
CVSS 5.5
CVE-2026-46914
HIGH
Oracle Solaris - Denial of Service
CVSS 7.1
CVE-2026-46910
CRITICAL
Oracle Corporation JD Edwards EnterpriseOne Tools < 9.2.26.2 - Denial of Service
CVSS 9.1
Details
Vulnerabilities
3,369
Exploit Likelihood
High