CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,094 vulnerabilities with CWE-400
CVE-2026-4926 HIGH
path-to-regexp vulnerable to Denial of Service via sequential optional groups
CVSS 7.5
CVE-2026-3116 MEDIUM
Improper Input Validation in Zoom Plugin Webhook Handler
CVSS 4.9
CVE-2026-33287 HIGH
LiquidJS has Exponential Memory Amplification through its replace_first Filter $& Pattern
CVSS 7.5
CVE-2026-33285 HIGH
LiquidJS: memoryLimit Bypass through Negative Range Values Leads to Process Crash
CVSS 7.5
CVE-2026-26233 MEDIUM
Denial of Service via HTTP/2 single packet attack on login endpoint
CVSS 4.3
CVE-2026-20084 HIGH
Cisco IOS XE Software 16.6.1-16.6.10, 16.7.1 - Unauthenticated Denial of Service via BOOTP Packet Handling
CVSS 8.6
CVE-2026-33268 MEDIUM
Nanoleaf Lines unauthenticated firmware file store
CVSS 6.5
CVE-2026-28874 HIGH
iOS and iPadOS < 26.4 - Denial of Service
CVSS 7.5
CVE-2026-33538 HIGH
Parse Server: Denial of service via unindexed database query for unconfigured auth providers
CVSS 7.5
CVE-2026-33474 MEDIUM
Vikunja Affected by DoS via Image Preview Generation
CVSS 6.5
CVE-2026-30662 MEDIUM
ConcreteCMS 9.4.7 - Authenticated Denial of Service via File Manager Bulk Download
CVSS 6.5
CVE-2026-30653 HIGH
free5gc < 4.2.0 - Denial of Service via AMF HandleAuthenticationFailure
CVSS 7.5
CVE-2026-4727 HIGH
Denial-of-service in the Libraries component in NSS
CVSS 7.5
CVE-2026-4726 HIGH
Firefox and Thunderbird - Denial of Service in XML Component
CVSS 7.5
CVE-2026-4704 HIGH
Denial-of-service in the WebRTC: Signaling component
CVSS 7.5
CVE-2026-33176 HIGH
ActiveSupport < 8.1.2.1, < 8.0.4.1, < 7.2.3.1 - Denial of Service via BigDecimal Scientific Notation Expansion
CVSS 7.5
CVE-2026-33169 MEDIUM
Active Support <8.1.2.1/8.0.4.1/7.2.3.1 - DoS
CVSS 5.3
CVE-2026-4539 LOW
pygments archetype.py AdlLexer redos
CVSS 3.3
CVE-2026-33204 HIGH
SimpleJWT <1.1.1 PBES2 JWE Header - Denial of Service
CVSS 7.5
CVE-2026-33155 HIGH
DeepDiff has Memory Exhaustion DoS through SAFE_TO_IMPORT
CVSS 7.5
CVE-2026-33123 MEDIUM
pypdf has inefficient decoding of array-based streams
CVSS 6.5
CVE-2026-25667 HIGH
.NET 8.0.0-8.0.21 and 9.0.0-9.0.10 - Uncontrolled Resource Consumption via Crafted QUIC Packet
CVSS 7.5
CVE-2026-29856 HIGH
aaPanel 7.57.0 - Regular Expression Denial of Service in VirtualHost Configuration Parser
CVSS 7.5
CVE-2026-27980 HIGH
Next.js: Unbounded next/image disk cache growth can exhaust storage
CVSS 7.5
CVE-2026-25771 MEDIUM
Wazuh Vulnerable to Denial of Service via Synchronous I/O Blocking in Asynchronous Authentication Middleware
CVSS 5.3
Details
Vulnerabilities 3,094
Exploit Likelihood High