CWE-400
High likelihoodUncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
3,371 vulnerabilities with CWE-400
CVE-2026-7493
MEDIUM
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.11.5 - Unauthenticated Denial of Service
CVSS 5.3
CVE-2026-48593
MEDIUM
Unbounded range expansion in cron describe causes memory exhaustion in oban_web
CVE-2026-8856
HIGH
IBM HTTP Server is affected by multiple vulnerabilities
CVSS 7.7
CVE-2026-9496
HIGH
Pacote - Inefficient Regular Expression Complexity
CVSS 7.5
CVE-2026-47077
HIGH
Unbounded body accumulation in HTTP/3 response loop in hackney
CVSS 7.5
CVE-2026-47073
HIGH
Unbounded memory consumption in WebSocket client in hackney
CVSS 7.5
CVE-2026-47071
HIGH
SOCKS5 TLS upgrade ignores caller timeout in hackney
CVSS 7.5
CVE-2026-42626
MEDIUM
HP ENVY 5000 VERBASPP1N003.2237A.00 - Unauthenticated Denial of Service via Persistent TCP Connection to Port 9100
CVSS 5.9
CVE-2026-25680
MEDIUM
Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html
CVSS 6.5
CVE-2026-5755
MEDIUM
Mattermost - Denial of Service via Crafted TIFF File Upload
CVSS 6.5
CVE-2026-5308
MEDIUM
Missing request body size limits on Zoom plugin HTTP endpoints
CVSS 4.9
CVE-2026-42001
HIGH
PowerDNS Authoritative 4.9.0-4.9.14 and 5.0.0-5.0.4 - Denial of Service via Autoprimary SOA Query Validation
CVSS 7.5
CVE-2026-9137
HIGH
CSP Report Endpoint Log Flooding via Incorrect Size Limit
CVSS 7.5
CVE-2026-45498
MEDIUM
KEV
Microsoft Defender Denial of Service Vulnerability
CVSS 4.0
CVE-2026-24215
MEDIUM
NVIDIA Triton Inference Server < 26.03 - Uncontrolled Resource Consumption in DALI Backend
CVSS 5.7
CVE-2026-8968
HIGH
Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component
CVSS 7.5
CVE-2026-33232
HIGH
AutoGPT: Unauthenticated DoS via Disk Space Exhaustion
CVSS 7.5
CVE-2026-8769
MEDIUM
vercel ai provider-utils response-handler.ts createJsonErrorResponseHandler resource consumption
CVSS 4.3
CVE-2026-38728
HIGH
Nodemailer smtp_server <3.18.3 - DoS
CVSS 7.5
CVE-2026-42304
HIGH
Twisted: Denial of Service (DoS) in twisted.names via Crafted DNS Compression Pointer Chains
CVSS 7.5
CVE-2026-33378
MEDIUM
Grafana Data Source Plugin: DoS (OOM) via Negative Interval Injection in $__timeGroup Macro
CVSS 6.5
CVE-2026-44248
MEDIUM
Netty: Resource exhaustion in MqttDecoder
CVSS 5.3
CVE-2026-42587
HIGH
Netty < 4.1.133.Final/4.2.13.Final HttpContentDecompressor - Decompression Bomb Denial of Service
CVSS 7.5
CVE-2026-42583
HIGH
Netty: Lz4FrameDecoder resource exhaustion
CVSS 7.5
CVE-2026-42579
HIGH
Netty: DNS Codec Input Validation Bypass in Netty (Encoder + Decoder)
CVSS 7.5
Details
Vulnerabilities
3,371
Exploit Likelihood
High