CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,367 vulnerabilities with CWE-400
CVE-2026-28932 MEDIUM
Apple macOS - Denial of Service
CVSS 5.5
CVE-2026-66144 HIGH
Apache Neethi: Remote PolicyReference fetch lacks resource bounds
CVSS 7.5
CVE-2026-66143 HIGH
Apache Neethi: Missing global alternative-output budget across policy computation paths
CVSS 7.5
CVE-2026-66142 HIGH
Apache Neethi: Uncontrolled recursion in policy processing
CVSS 7.5
CVE-2026-14257 HIGH
brace-expansion DoS via unbounded expansion length causing an out-of-memory process crash
CVSS 7.5
CVE-2026-21723 MEDIUM
Grafana OSS Alertmanager Templates Test Endpoint - Denial of Service
CVSS 5.3
CVE-2026-38763 MEDIUM
Protegent 360 2.0.0.4 - Denial of Service via Function sub_13828
CVSS 5.5
CVE-2026-45820 MEDIUM
101arrowz Fflate - Uncontrolled Resource Consumption
CVE-2026-63263 MEDIUM
Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
CVSS 6.5
CVE-2026-63261 MEDIUM
Uncontrolled Resource Consumption in Kibana Leading to Denial of Service
CVSS 6.5
CVE-2026-63260 MEDIUM
Uncontrolled Resource Consumption in Kibana Leading to Denial of Service
CVSS 6.5
CVE-2026-56819 HIGH
Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS)
CVSS 7.5
CVE-2026-62518 HIGH
Oracle Production Scheduling < 12.2.15 - Denial of Service
CVSS 7.6
CVE-2026-62508 LOW
Oracle Time And Labor < 12.2.15 - Denial of Service
CVSS 3.1
CVE-2026-62465 MEDIUM
Oracle Hrms (us) < 12.2.15 - Denial of Service
CVSS 6.6
CVE-2026-61247 MEDIUM
Oracle Workflow < 12.2.15 - Denial of Service
CVSS 4.8
CVE-2026-61195 MEDIUM
Oracle Agile Engineering Data Management - Denial of Service
CVSS 6.5
CVE-2026-61194 MEDIUM
Oracle Agile Engineering Data Management - Denial of Service
CVSS 6.5
CVE-2026-61192 MEDIUM
Oracle Agile Engineering Data Management - Denial of Service
CVSS 5.3
CVE-2026-61186 CRITICAL
Oracle Agile Engineering Data Management - Denial of Service
CVSS 9.4
CVE-2026-61165 HIGH
Oracle Commerce Guided Search Platform Services - Denial of Service
CVSS 7.1
CVE-2026-61160 HIGH
Oracle Commerce Guided Search / Oracle Commerce Experience Manager - Denial of Service
CVSS 8.1
CVE-2026-61155 CRITICAL
Oracle Commerce Guided Search Platform Services - Denial of Service
CVSS 9.1
CVE-2026-61147 MEDIUM
Oracle Commerce Guided Search / Oracle Commerce Experience Manager - Denial of Service
CVSS 6.2
CVE-2026-61144 MEDIUM
Oracle Corporation MySQL Server - Denial of Service
CVSS 4.9
Details
Vulnerabilities 3,367
Exploit Likelihood High