CWE-400
High likelihoodUncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
3,369 vulnerabilities with CWE-400
CVE-2026-46866
HIGH
Oracle Enterprise Manager Base Platform - Denial of Service
CVSS 8.2
CVE-2026-46863
HIGH
Oracle Corporation MySQL Server - Denial of Service
CVSS 7.5
CVE-2026-46862
HIGH
Oracle Corporation MySQL Router - Denial of Service
CVSS 7.5
CVE-2026-12325
MEDIUM
Denial-of-service in the Graphics: ImageLib component
CVSS 6.5
CVE-2026-12319
MEDIUM
Denial-of-service in the Audio/Video: Playback component
CVSS 6.5
CVE-2026-50889
HIGH
LLDAP 0.6.2 - Denial of Service via Crafted Refresh-Token Header
CVSS 7.5
CVE-2026-50882
HIGH
anna-is-cute paste 0.1.1 - Denial of Service via /api/v0/pastes Endpoint
CVSS 7.5
CVE-2026-50879
HIGH
linx-server 2.3.8 - Denial of Service via Crafted POST Request
CVSS 7.5
CVE-2026-50878
HIGH
Feuerhamster MailForm 1.1.0 - Denial of Service via Attachment Handling
CVSS 7.5
CVE-2026-41708
HIGH
Spring Cloud Sleuth instrumentation of Spring TX DoS vulnerability
CVSS 7.5
CVE-2026-39197
MEDIUM
Vector 0.54.0 - Denial of Service via /util/http/prelude.rs Endpoint
CVSS 6.5
CVE-2026-5079
HIGH
multer vulnerable to Denial of Service via deeply nested field names
CVSS 7.5
CVE-2026-50011
HIGH
Netty has unbounded pre-allocation in RedisArrayAggregator from RESP array length
CVSS 7.5
CVE-2026-48043
MEDIUM
netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion
CVSS 5.3
CVE-2026-47244
MEDIUM
Netty HTTP/2: Advertised MAX_CONCURRENT_STREAMS are not enforced
CVSS 5.3
CVE-2026-50645
HIGH
Apache CXF: No restriction on attachment headers per message
CVSS 7.5
CVE-2026-45169
HIGH
Idira Privileged Access Manager (PAM) Self-Hosted Vault: Denial of Service due to Unexpected Input Processing
CVSS 8.6
CVE-2026-44892
HIGH
Netty has a Vulnerable Default Configuration Which Leads to Denial of Service via Unbounded HTTP/3 Header Size
CVSS 7.5
CVE-2026-44890
HIGH
Netty has Unbounded Direct Memory Consumption in its RedisDecoder
CVSS 7.5
CVE-2026-44250
HIGH
Netty: Memory Exhaustion in RedisArrayAggregator due to Deeply Nested Arrays
CVSS 7.5
CVE-2026-45802
MEDIUM
FPDI: Memory Exhaustion and Endless Loop in FPDI leads to Denial of Service
CVE-2026-44496
HIGH
Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection
CVSS 7.5
CVE-2026-5497
HIGH
Unbounded Frame Count in video/jpeg Base64 Data URL Processing Leads to OOM DoS in vllm-project/vllm
CVSS 7.5
CVE-2026-47734
MEDIUM
Dulwich has unbounded memory allocation in receive-pack from crafted thin packs
CVSS 5.7
CVE-2026-46689
HIGH
Kanidm: Unauthenticated process abort via SCIM filter stack exhaustion
Details
Vulnerabilities
3,369
Exploit Likelihood
High