CWE-400
High likelihoodUncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
3,371 vulnerabilities with CWE-400
CVE-2026-34271
MEDIUM
MySQL Server 8.0.0-8.0.45, 8.4.0-8.4.8, 9.0.0-9.6.0 - Denial of Service in Group Replication Plugin
CVSS 6.5
CVE-2026-34270
MEDIUM
MySQL Server 8.0.0-8.0.45, 8.4.0-8.4.8, 9.0.0-9.6.0 - Denial of Service in Group Replication Plugin
CVSS 6.5
CVE-2026-34267
MEDIUM
MySQL Server 8.0.0-8.0.45 - Authenticated Denial of Service in Server Optimizer
CVSS 4.9
CVE-2026-22021
MEDIUM
Oracle Java SE & GraalVM for JDK - Unauthenticated Partial DoS via JSSE
CVSS 5.3
CVE-2026-22017
MEDIUM
MySQL Server 8.0.0-8.0.45, 8.4.0-8.4.8, 9.0.0-9.6.0 - Denial of Service in Optimizer
CVSS 6.5
CVE-2026-22009
MEDIUM
MySQL Server 8.0.0-8.0.45, 8.4.0-8.4.8, 9.0.0-9.6.0 - Denial of Service in Optimizer
CVSS 6.5
CVE-2026-22005
MEDIUM
MySQL Server 8.0.0-8.0.45, 8.4.0-8.4.8, 9.0.0-9.6.0 - Denial of Service in Server Optimizer
CVSS 4.9
CVE-2026-22004
MEDIUM
MySQL Server 8.0.0-8.0.45, 8.4.0-8.4.8, 9.0.0-9.6.0 - Authenticated Denial of Service in InnoDB
CVSS 4.9
CVE-2026-22003
MEDIUM
Oracle Java SE 8u481, 8u481-b50 and GraalVM Enterprise Edition 21.3.17 - Uncontrolled Resource Consumption in Hotspot
CVSS 6.0
CVE-2026-22002
MEDIUM
MySQL Server 8.0.0-8.0.45, 8.4.0-8.4.8, 9.0.0-9.6.0 - Denial of Service in Optimizer
CVSS 4.9
CVE-2026-21998
MEDIUM
MySQL Server 8.0.0-8.0.45, 8.4.0-8.4.8, 9.0.0-9.6.0 - Authenticated Denial of Service in Optimizer
CVSS 4.9
CVE-2026-6781
HIGH
Denial-of-service in the Audio/Video: Playback component
CVSS 7.5
CVE-2026-6780
HIGH
Denial-of-service in the Audio/Video: Playback component
CVSS 7.5
CVE-2026-6777
MEDIUM
Mozilla Firefox and Thunderbird 150 - DNS Component Input Validation Issue
CVSS 5.3
CVE-2026-39396
LOW
OpenBao has Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)
CVSS 3.1
CVE-2026-39320
HIGH
Signal K Server <2.25.0 WebSocket Subscriptions - Regular Expression Denial of Service
CVSS 7.5
CVE-2026-6060
MEDIUM
OTRS 7.0.x-8.0.x, 2023.x-2025.x, <2026.3.x - Denial of Service via SQL Box Resource Consumption
CVSS 4.5
CVE-2026-6607
MEDIUM
lm-sys fastchat Worker API Endpoint api_generate resource consumption
CVSS 5.3
CVE-2026-6601
MEDIUM
Lagom WHMCS Template Datatables resource consumption
CVSS 4.3
CVE-2026-40347
MEDIUM
Python-Multipart affected by Denial of Service via large multipart preamble or epilogue data
CVSS 5.3
CVE-2026-40481
HIGH
monetr: Unauthenticated Stripe webhook reads attacker-sized request bodies before signature validation
CVSS 7.5
CVE-2026-40303
HIGH
zrok allows unauthenticated DoS via unbounded memory allocation in striped session cookie parsing
CVSS 7.5
CVE-2026-40192
HIGH
Pillow is vulnerable to a FITS GZIP decompression bomb
CVSS 7.5
CVE-2026-3505
HIGH
Unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion.
CVSS 7.5
CVE-2026-35034
MEDIUM
Jellyfin: Potential Application DoS from excessively large SyncPlay group names
CVSS 6.5
Details
Vulnerabilities
3,371
Exploit Likelihood
High