CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,371 vulnerabilities with CWE-400
CVE-2026-10156 MEDIUM
Open5GS nf-instances Endpoint nnrf-handler.c handle_amf_info resource consumption
CVSS 4.3
CVE-2026-46385 HIGH
iskorotkov/avro: CPU Exhaustion in Avro Decoder
CVSS 7.5
CVE-2026-45149 MEDIUM
brace-expansion: Large numeric range defeats documented `max` DoS protection
CVSS 6.5
CVE-2026-10069 HIGH
Shibby Tomato miniupnpd resource consumption
CVSS 7.5
CVE-2026-49324 MEDIUM
Indian Scout Bobber 2025 WCM brute-force
CVSS 4.6
CVE-2026-49094 MEDIUM
Uncontrolled Resource Consumption in Kibana Leading to Denial of Service
CVSS 6.5
CVE-2026-46843 MEDIUM
Oracle Rest Data Services < 26.1.0 - Denial of Service
CVSS 5.3
CVE-2026-46835 HIGH
Oracle Database Server < 23.26.2 - Denial of Service
CVSS 7.5
CVE-2026-46834 HIGH
Oracle Database Server < 23.26.2 - Denial of Service
CVSS 7.5
CVE-2026-46829 HIGH
Oracle Rest Data Services < 26.1.0 - Denial of Service
CVSS 7.5
CVE-2026-46775 CRITICAL
Oracle REST Data Services 24.2.0-26.1.0 - Authenticated Remote Code Execution via HTTPS
CVSS 9.9
CVE-2026-42400 MEDIUM
Uncontrolled Resource Consumption in Kibana Leading to Denial of Service
CVSS 6.5
CVE-2026-42399 MEDIUM
Uncontrolled Resource Consumption in Kibana Leading to Denial of Service
CVSS 6.5
CVE-2026-35277 HIGH
Oracle REST Data Services 24.2.0-26.1.0 - Authenticated Unauthorized Data Access and Modification via HTTPS
CVSS 8.1
CVE-2026-35266 HIGH
Oracle Rest Data Services < 26.1.0 - Denial of Service
CVSS 7.9
CVE-2026-33464 MEDIUM
Uncontrolled Resource Consumption in Kibana Leading to Denial of Service
CVSS 6.5
CVE-2026-44796 MEDIUM
Nautobot: Object bulk rename UI actions vulnerable to denial of service by crafted regular expression (REDoS)
CVSS 6.5
CVE-2026-48525 MEDIUM
PyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload segment in b64=false detached JWS
CVSS 5.3
CVE-2026-48155 MEDIUM
pypdf: Possible large memory usage for large offsets for layout mode text
CVSS 5.5
CVE-2026-44247 MEDIUM
Volcano: Webhook server vulnerable to OOM due to unbounded HTTP request body size
CVSS 6.8
CVE-2026-45047 HIGH
bird-lg-go: Fatal Out-of-Memory (OOM) Denial of Service via Unbounded JSON Decoding
CVSS 7.5
CVE-2026-7528 HIGH
Unauthenticated File Upload Vulnerability Allows Disk Space Exhaustion and Path Disclosure in Langflow OSS
CVSS 7.1
CVE-2026-6052 MEDIUM
IBM® Db2® is vulnerable to running out of memory when executing certain queries with MDC tables
CVSS 6.5
CVE-2026-6051 MEDIUM
IBM® Db2® is vulnerable to a denial of service when executing a specially crafted query with a small statement heap
CVSS 5.5
CVE-2026-4410 MEDIUM
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a denial of service
CVSS 4.8
Details
Vulnerabilities 3,371
Exploit Likelihood High