CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,371 vulnerabilities with CWE-400
CVE-2026-44456 MEDIUM
Hono: bodyLimit() can be bypassed for chunked / unknown-length requests
CVSS 6.5
CVE-2026-44296 HIGH
Deskflow: TLS multiplexer DoS on failed `SSL_accept`
CVSS 7.5
CVE-2026-44242 LOW
Micronaut Framework: Unbounded bundleCache in ResourceBundleMessageSource Allows Memory Exhaustion via Accept-Language Header
CVSS 3.7
CVE-2026-44241 HIGH
Micronaut Framework: Unbounded formattersCache in TimeConverterRegistrar Allows Memory Exhaustion via Accept-Language Header
CVSS 7.5
CVE-2026-42544 HIGH
Granian: Unauthenticated DoS via WebSocket subprotocol header panic
CVSS 7.5
CVE-2026-44240 HIGH
basic-ftp allows a malicious FTP server to cause client-side denial of service via unbounded multiline control response buffering
CVSS 7.5
CVE-2026-34678 MEDIUM
CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)
CVSS 6.2
CVE-2026-34677 MEDIUM
CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)
CVSS 6.2
CVE-2026-34673 MEDIUM
CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)
CVSS 6.2
CVE-2026-34665 HIGH
CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)
CVSS 7.5
CVE-2026-34651 HIGH
Adobe Commerce | Uncontrolled Resource Consumption (CWE-400)
CVSS 7.5
CVE-2026-34650 HIGH
Adobe Commerce | Uncontrolled Resource Consumption (CWE-400)
CVSS 7.5
CVE-2026-34649 HIGH
Adobe Commerce | Uncontrolled Resource Consumption (CWE-400)
CVSS 7.5
CVE-2026-34648 HIGH
Adobe Commerce | Uncontrolled Resource Consumption (CWE-400)
CVSS 7.5
CVE-2026-23824 HIGH
Unauthenticated Denial-of-Service via Crafted Messages in a Network Protocol Handling Component
CVSS 7.5
CVE-2026-44167 HIGH
phpseclib: CVE-2024-27355 mitigation bypass — OID amplification DoS in ASN1::decodeOID()
CVSS 7.5
CVE-2026-42006 MEDIUM
OX Dovecot Pro < 3.0.5, < 3.1.4, < 2.4.3 - Unauthenticated Uncontrolled Resource Consumption via IMAP Bracing
CVSS 4.3
CVE-2026-40016 MEDIUM
OX Dovecot Pro < 2.3.0 - Uncontrolled Resource Consumption via Sieve Script CPU Limit Bypass
CVSS 5.3
CVE-2026-43653 MEDIUM
iOS and iPadOS < 18.7.9 - Denial of Service via Uncontrolled Resource Consumption
CVSS 6.2
CVE-2026-28967 MEDIUM
iOS and iPadOS < 18.7.7 and < 26.4 - Denial of Service
CVSS 4.9
CVE-2026-28908 HIGH
macOS < 14.8.7, < 15.7.7, < 26.5 - Denial of Service via File System Modification
CVSS 7.5
CVE-2026-28872 HIGH
iOS and iPadOS < 18.7.9 and < 26.4 - Denial of Service via Resource Exhaustion
CVSS 7.5
CVE-2026-8319 MEDIUM
aiwaves-cn agents cheshire_cat_core stray_cat.py recall_relevant_memories_to_working_memory resource consumption
CVSS 5.3
CVE-2026-7790 HIGH
Unbounded chunk-size hex digits in cowlib cause quadratic CPU and memory DoS
CVSS 7.5
CVE-2026-31247 HIGH
Docling JATS XML Backend thru 2.61.0 - XML Entity Expansion Denial of Service
CVSS 7.5
Details
Vulnerabilities 3,371
Exploit Likelihood High