CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

2,909 vulnerabilities with CWE-400
CVE-2026-34281 MEDIUM
Oracle Corporation Oracle Solaris < 11.4 - Denial of Service
CVSS 6.5
CVE-2026-34278 MEDIUM
Oracle Corporation MySQL Server < 8.0.45 - Denial of Service
CVSS 4.9
CVE-2026-34277 MEDIUM
Oracle Corporation PeopleSoft Enterprise PeopleTools < 8.62 - Denial of Service
CVSS 6.6
CVE-2026-34276 MEDIUM
Oracle Corporation MySQL Server < 8.0.45 - Denial of Service
CVSS 6.5
CVE-2026-34272 MEDIUM
Oracle Corporation MySQL Server < 9.6.0 - Denial of Service
CVSS 6.5
CVE-2026-34271 MEDIUM
Oracle Corporation MySQL Server < 8.0.45 - Denial of Service
CVSS 6.5
CVE-2026-34270 MEDIUM
Oracle Corporation MySQL Server < 8.0.45 - Denial of Service
CVSS 6.5
CVE-2026-34267 MEDIUM
Oracle Corporation MySQL Server < 8.0.45 - Denial of Service
CVSS 4.9
CVE-2026-22021 MEDIUM
Oracle Corporation Oracle Java SE < 8u481 - Denial of Service
CVSS 5.3
CVE-2026-22017 MEDIUM
Oracle Corporation MySQL Server < 8.0.45 - Denial of Service
CVSS 6.5
CVE-2026-22009 MEDIUM
Oracle Corporation MySQL Server < 8.0.45 - Denial of Service
CVSS 6.5
CVE-2026-22005 MEDIUM
Oracle Corporation MySQL Server < 8.0.45 - Denial of Service
CVSS 4.9
CVE-2026-22004 MEDIUM
Oracle Corporation MySQL Server < 8.0.45 - Denial of Service
CVSS 4.9
CVE-2026-22003 MEDIUM
Oracle Corporation Oracle Java SE < 8u481 - Denial of Service
CVSS 6.0
CVE-2026-22002 MEDIUM
Oracle Corporation MySQL Server < 8.0.45 - Denial of Service
CVSS 4.9
CVE-2026-21998 MEDIUM
Oracle Corporation MySQL Server < 8.0.45 - Denial of Service
CVSS 4.9
CVE-2026-6781 HIGH
Denial-of-service in the Audio/Video: Playback component
CVSS 7.5
CVE-2026-6780 HIGH
Denial-of-service in the Audio/Video: Playback component
CVSS 7.5
CVE-2026-6777 MEDIUM
Other issue in the Networking: DNS component
CVSS 5.3
CVE-2026-39396 LOW
OpenBao has Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)
CVSS 3.1
CVE-2026-39320 HIGH
Signal K Server has an Unauthenticated Regular Expression Denial of Service (ReDoS) via WebSocket Subscription Paths
CVSS 7.5
CVE-2026-6060 MEDIUM
Otrs < 7.0.x - Denial of Service
CVSS 4.5
CVE-2026-6607 MEDIUM
lm-sys fastchat Worker API Endpoint api_generate resource consumption
CVSS 5.3
CVE-2026-6601 MEDIUM
Lagom WHMCS Template Datatables resource consumption
CVSS 4.3
CVE-2026-40347 MEDIUM
Python-Multipart affected by Denial of Service via large multipart preamble or epilogue data
CVSS 5.3
Details
Vulnerabilities 2,909
Exploit Likelihood High