CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,371 vulnerabilities with CWE-400
CVE-2026-40983 HIGH
Micrometer gRPC server instrumentation DoS vulnerability
CVSS 7.5
CVE-2026-11611 MEDIUM
389-ds-base: 389-ds-base: content sync plugin unbounded queue growth and race conditions
CVSS 6.5
CVE-2026-11478 LOW
kokke tiny-regex-c Pattern re.c matchstar redos
CVSS 3.3
CVE-2026-47707 MEDIUM
Strawberry GraphQL's Bypass of MaxAliasesLimiter via Fragment Spreads leading to GraphQL Alias Amplification
CVSS 5.3
CVE-2026-47706 MEDIUM
Strawberry GraphQL 0.71.0-0.315.6 Fragments - Denial of Service
CVSS 5.3
CVE-2026-28318 HIGH KEV
SolarWinds Serv-U Unauthenticated Denial of Service Vulnerability
CVSS 7.5
CVE-2026-10802 MEDIUM
keystonejs keystone GraphQL API Endpoint output-field.ts resource consumption
CVSS 4.3
CVE-2026-50212 MEDIUM
Acer Connect M6E 5G Portable WiFi Router - Arbitrary Remote Device Unbinding
CVSS 6.5
CVE-2026-36605 MEDIUM
Mercusys AC12G (EU) V1 Firmware AC12G(EU)_V1_200909 - Denial of Service via Crafted Incomplete HTTP Requests
CVSS 6.5
CVE-2026-10705 LOW
dask HLL hyperloglog.py nunique_approx resource consumption
CVSS 3.1
CVE-2026-10692 MEDIUM
johnhuang316 code-index-mcp search_code_advanced is_safe_regex_pattern redos
CVSS 4.3
CVE-2026-10691 MEDIUM
wonderwhy-er DesktopCommanderMCP start_search search-manager.ts redos
CVSS 4.3
CVE-2026-10650 MEDIUM
warmcat libwebsockets SSH Protocol sshd.c lws_ssh_parse_plaintext resource consumption
CVSS 5.3
CVE-2026-42342 HIGH
React Router vulnerable to DoS via unbounded path expansion in __manifest endpoint
CVSS 7.5
CVE-2026-42073 MEDIUM
OpenClaude's MCP OAuth Callback: State Check Bypass via error Param Leads to DoS
CVSS 6.5
CVE-2026-45680 MEDIUM
OpenTelemetry eBPF Instrumentation: Unbounded BPF internal metrics replay can exhaust CPU
CVSS 5.9
CVE-2026-10291 MEDIUM
Enderfga claw-orchestrator <= 3.7.0 - Inefficient Regular Expression Complexity in Session Grep Endpoint
CVSS 4.3
CVE-2026-0074 MEDIUM
Android 14-16 LauncherProcessImageListener - Resource Exhaustion Denial of Service
CVSS 5.5
CVE-2026-0069 MEDIUM
ApkChecksums.java - Denial of Service via Resource Exhaustion in verifySignature
CVSS 5.5
CVE-2026-0042 MEDIUM
Android 14-16 UBSan Runtime - Resource Exhaustion Denial of Service
CVSS 5.5
CVE-2026-37234 HIGH
FlexRIC 2.0.0 - Resource Exhaustion via Stale Subscription State Leak
CVSS 8.2
CVE-2026-49361 HIGH
Apache Fluss Netty Frame Decoder Memory Exhaustion Vulnerability
CVSS 7.5
CVE-2026-10224 MEDIUM
NousResearch hermes-agent Webhook Endpoint feishu.py _handle_webhook_request resource consumption
CVSS 5.3
CVE-2026-48208 MEDIUM
OTRS - Denial-of-Service via SVG Rendering in Ticket
CVSS 6.5
CVE-2026-48187 MEDIUM
OTRS Email Handling - Resource Exhaustion Denial of Service
CVSS 5.7
Details
Vulnerabilities 3,371
Exploit Likelihood High