CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,369 vulnerabilities with CWE-400
CVE-2026-46679 HIGH
libp2p: Memory DoS via subscription flood of unique topics
CVSS 7.5
CVE-2026-46522 HIGH
ImageMagick - Infinite Loop in the MIFF decoder can lead to CPU exhaustion
CVSS 7.5
CVE-2026-45783 HIGH
libp2p: Unvalidated PUT_VALUE records allow unbounded disk exhaustion on DHT server nodes
CVSS 7.5
CVE-2026-45664 MEDIUM
ImageMagick: Policy Bypass in MNG coder could
CVSS 5.3
CVE-2026-45031 MEDIUM
ImageMagick: Policy Bypass in PSD decoder
CVSS 5.3
CVE-2026-10143 HIGH
kafka-python prior to 2.3.2 DoS via SCRAM Iteration Count in scram.py
CVSS 7.5
CVE-2026-41721 MEDIUM
Spring Data Commons Denial of Service via Data Binding
CVSS 5.9
CVE-2026-41711 MEDIUM
Spring Data Commons - Potential Denial of Service Through Crafted Sort Parameters
CVSS 5.9
CVE-2026-41695 HIGH
Denial of Service in Spring Data Commons Property Path Resolution
CVSS 7.5
CVE-2026-40988 HIGH
Unbounded DEFLATE Inflation in SAML 2.0 Service Provider
CVSS 7.5
CVE-2026-46374 HIGH
SQLFluff: Uncontrolled Resource Consumption in Parser
CVSS 7.5
CVE-2026-47905 MEDIUM
CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)
CVSS 6.2
CVE-2026-47904 MEDIUM
CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)
CVSS 6.2
CVE-2026-47902 MEDIUM
CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)
CVSS 6.2
CVE-2026-34713 HIGH
CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)
CVSS 7.5
CVE-2026-36724 MEDIUM
FastapiAdmin 2.2.0 - Authenticated Denial of Service via Scheduled Task Func Field Manipulation
CVSS 6.5
CVE-2026-49842 HIGH
FreeSWITCH: Pre-authentication bandwidth amplification via `mod_verto` speed-test frames
CVSS 7.5
CVE-2026-49160 HIGH
Microsoft Windows HTTP.sys HTTP/2 - Denial of Service
CVSS 7.5
CVE-2026-45591 HIGH
Microsoft ASP.NET Core - Unauthenticated Denial of Service
CVSS 7.5
CVE-2026-49762 MEDIUM
Unbounded integer parsing in the Version module enables CPU and memory exhaustion denial of service
CVE-2026-11790 MEDIUM
389-ds-base: 389-ds-base: pbkdf2 password storage plugin unbounded iteration count denial of service
CVSS 4.9
CVE-2026-41842 HIGH
Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux
CVSS 7.5
CVE-2026-40984 HIGH
Micrometer HTTP server instrumentations DoS vulnerability
CVSS 7.5
CVE-2026-40983 HIGH
Micrometer gRPC server instrumentation DoS vulnerability
CVSS 7.5
CVE-2026-11611 MEDIUM
389-ds-base: 389-ds-base: content sync plugin unbounded queue growth and race conditions
CVSS 6.5
Details
Vulnerabilities 3,369
Exploit Likelihood High