CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,369 vulnerabilities with CWE-400
CVE-2026-46866 HIGH
Oracle Enterprise Manager Base Platform - Denial of Service
CVSS 8.2
CVE-2026-46863 HIGH
Oracle Corporation MySQL Server - Denial of Service
CVSS 7.5
CVE-2026-46862 HIGH
Oracle Corporation MySQL Router - Denial of Service
CVSS 7.5
CVE-2026-12325 MEDIUM
Denial-of-service in the Graphics: ImageLib component
CVSS 6.5
CVE-2026-12319 MEDIUM
Denial-of-service in the Audio/Video: Playback component
CVSS 6.5
CVE-2026-50889 HIGH
LLDAP 0.6.2 - Denial of Service via Crafted Refresh-Token Header
CVSS 7.5
CVE-2026-50882 HIGH
anna-is-cute paste 0.1.1 - Denial of Service via /api/v0/pastes Endpoint
CVSS 7.5
CVE-2026-50879 HIGH
linx-server 2.3.8 - Denial of Service via Crafted POST Request
CVSS 7.5
CVE-2026-50878 HIGH
Feuerhamster MailForm 1.1.0 - Denial of Service via Attachment Handling
CVSS 7.5
CVE-2026-41708 HIGH
Spring Cloud Sleuth instrumentation of Spring TX DoS vulnerability
CVSS 7.5
CVE-2026-39197 MEDIUM
Vector 0.54.0 - Denial of Service via /util/http/prelude.rs Endpoint
CVSS 6.5
CVE-2026-5079 HIGH
multer vulnerable to Denial of Service via deeply nested field names
CVSS 7.5
CVE-2026-50011 HIGH
Netty has unbounded pre-allocation in RedisArrayAggregator from RESP array length
CVSS 7.5
CVE-2026-48043 MEDIUM
netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion
CVSS 5.3
CVE-2026-47244 MEDIUM
Netty HTTP/2: Advertised MAX_CONCURRENT_STREAMS are not enforced
CVSS 5.3
CVE-2026-50645 HIGH
Apache CXF: No restriction on attachment headers per message
CVSS 7.5
CVE-2026-45169 HIGH
Idira Privileged Access Manager (PAM) Self-Hosted Vault: Denial of Service due to Unexpected Input Processing
CVSS 8.6
CVE-2026-44892 HIGH
Netty has a Vulnerable Default Configuration Which Leads to Denial of Service via Unbounded HTTP/3 Header Size
CVSS 7.5
CVE-2026-44890 HIGH
Netty has Unbounded Direct Memory Consumption in its RedisDecoder
CVSS 7.5
CVE-2026-44250 HIGH
Netty: Memory Exhaustion in RedisArrayAggregator due to Deeply Nested Arrays
CVSS 7.5
CVE-2026-45802 MEDIUM
FPDI: Memory Exhaustion and Endless Loop in FPDI leads to Denial of Service
CVE-2026-44496 HIGH
Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection
CVSS 7.5
CVE-2026-5497 HIGH
Unbounded Frame Count in video/jpeg Base64 Data URL Processing Leads to OOM DoS in vllm-project/vllm
CVSS 7.5
CVE-2026-47734 MEDIUM
Dulwich has unbounded memory allocation in receive-pack from crafted thin packs
CVSS 5.7
CVE-2026-46689 HIGH
Kanidm: Unauthenticated process abort via SCIM filter stack exhaustion
Details
Vulnerabilities 3,369
Exploit Likelihood High