CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,371 vulnerabilities with CWE-400
CVE-2026-41680 HIGH
Marked: OOM Denial of Service via Infinite Recursion in marked Tokenizer
CVSS 7.5
CVE-2026-31052 MEDIUM
Hostbill 2025-11-24/2025-12-01 - DoS
CVSS 5.3
CVE-2026-31051 LOW
Hostbill 2025-11-24/2025-12-01 - DoS
CVSS 3.8
CVE-2026-21728 HIGH
Tempo query limit results in unbounded memory allocation
CVSS 7.5
CVE-2026-41324 HIGH
basic-ftp vulnerable to denial of service via unbounded memory consumption in Client.list()
CVSS 7.5
CVE-2026-41309 HIGH
Open Source Social Network (OSSN) Vulnerable to Resource Exhaustion via Malicious Image Processing
CVSS 8.2
CVE-2026-33610 MEDIUM
Possible file descriptor exhaustion in forward-dnsupdate
CVSS 5.9
CVE-2026-6844 MEDIUM
Binutils: binutils: denial of service vulnerabilities in readelf via crafted elf files
CVSS 5.5
CVE-2026-6022 HIGH
Uncontrolled Resource Consumption Vulnerability in Telerik UI for ASP.NET AJAX
CVSS 7.5
CVE-2026-6416 LOW
Tanium addressed an uncontrolled resource consumption vulnerability in Interact.
CVSS 2.7
CVE-2026-41146 HIGH
facil.io and downstream iodine ruby gem vulnerable to uncontrolled resource consumption and loop with unreachable exit condition
CVE-2026-41135 HIGH
free5GC PCF: Memory Leak via CORS Middleware Registration in HTTP Handler Leads to Denial of Service
CVSS 7.5
CVE-2026-6797 MEDIUM
Sanluan PublicCMS DocToHtmlUtils.java ZipSecureFile.setMinflateRatio resource consumption
CVSS 4.3
CVE-2026-40924 MEDIUM
Tekton Pipelines: HTTP Resolver Unbounded Response Body Read Enables Denial of Service via Memory Exhaustion
CVSS 6.5
CVE-2026-34308 MEDIUM
MySQL Server 8.0.0-8.0.45, 8.4.0-8.4.8, 9.0.0-9.6.0 - Denial of Service in JSON Component
CVSS 6.5
CVE-2026-34304 MEDIUM
MySQL Server 8.0.0-8.0.45, 8.4.0-8.4.8, 9.0.0-9.6.0 - Authenticated Denial of Service in InnoDB
CVSS 4.9
CVE-2026-34303 MEDIUM
MySQL Server 8.0.0-8.0.45, 8.4.0-8.4.8, 9.0.0-9.6.0 - Denial of Service in Optimizer
CVSS 6.5
CVE-2026-34293 MEDIUM
MySQL Server 8.0.0-8.0.45 - Authenticated Denial of Service in DML Component
CVSS 4.9
CVE-2026-34290 HIGH
Oracle Corporation Oracle Identity Manager Connector < 12.2.1.4.0 - Denial of Service
CVSS 7.5
CVE-2026-34282 HIGH
Oracle Java SE & GraalVM DoS via Networking Component
CVSS 7.5
CVE-2026-34281 MEDIUM
Oracle Solaris 11.4 - Denial of Service in Kernel
CVSS 6.5
CVE-2026-34278 MEDIUM
MySQL Server 8.0.0-8.0.45 - Authenticated Denial of Service in Server Optimizer
CVSS 4.9
CVE-2026-34277 MEDIUM
PeopleSoft Enterprise PeopleTools 8.61-8.62 - Authenticated Improper Access Control in Fluid Core
CVSS 6.6
CVE-2026-34276 MEDIUM
MySQL Server 8.0.0-8.0.45, 8.4.0-8.4.8, 9.0.0-9.6.0 - Denial of Service in Group Replication Plugin
CVSS 6.5
CVE-2026-34272 MEDIUM
MySQL Server 9.0.0-9.6.0 - Denial of Service in Optimizer
CVSS 6.5
Details
Vulnerabilities 3,371
Exploit Likelihood High