CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,094 vulnerabilities with CWE-400
CVE-2026-46374 HIGH
SQLFluff: Uncontrolled Resource Consumption in Parser
CVSS 7.5
CVE-2026-47905 MEDIUM
CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)
CVSS 6.2
CVE-2026-47904 MEDIUM
CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)
CVSS 6.2
CVE-2026-47902 MEDIUM
CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)
CVSS 6.2
CVE-2026-34713 HIGH
CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)
CVSS 7.5
CVE-2026-36724 MEDIUM
FastapiAdmin 2.2.0 - Authenticated Denial of Service via Scheduled Task Func Field Manipulation
CVSS 6.5
CVE-2026-49842 HIGH
FreeSWITCH: Pre-authentication bandwidth amplification via `mod_verto` speed-test frames
CVSS 7.5
CVE-2026-49160 HIGH
Microsoft Windows HTTP.sys HTTP/2 - Denial of Service
CVSS 7.5
CVE-2026-45591 HIGH
Microsoft ASP.NET Core - Unauthenticated Denial of Service
CVSS 7.5
CVE-2026-49762 MEDIUM
Unbounded integer parsing in the Version module enables CPU and memory exhaustion denial of service
CVE-2026-11790 MEDIUM
389-ds-base: 389-ds-base: pbkdf2 password storage plugin unbounded iteration count denial of service
CVSS 4.9
CVE-2026-41842 HIGH
Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux
CVSS 7.5
CVE-2026-41840 MEDIUM
Spring Framework Denial of Service via Multipart Requests in WebFlux
CVSS 5.9
CVE-2026-40984 HIGH
Micrometer HTTP server instrumentations DoS vulnerability
CVSS 7.5
CVE-2026-40983 HIGH
Micrometer gRPC server instrumentation DoS vulnerability
CVSS 7.5
CVE-2026-11611 MEDIUM
389-ds-base: 389-ds-base: content sync plugin unbounded queue growth and race conditions
CVSS 6.5
CVE-2026-11478 LOW
kokke tiny-regex-c Pattern re.c matchstar redos
CVSS 3.3
CVE-2026-47707 MEDIUM
Strawberry GraphQL's Bypass of MaxAliasesLimiter via Fragment Spreads leading to GraphQL Alias Amplification
CVSS 5.3
CVE-2026-47706 MEDIUM
Strawberry GraphQL 0.71.0-0.315.6 Fragments - Denial of Service
CVSS 5.3
CVE-2026-28318 HIGH KEV
SolarWinds Serv-U Unauthenticated Denial of Service Vulnerability
CVSS 7.5
CVE-2026-10802 MEDIUM
keystonejs keystone GraphQL API Endpoint output-field.ts resource consumption
CVSS 4.3
CVE-2026-50212 MEDIUM
Acer Connect M6E 5G Portable WiFi Router - Arbitrary Remote Device Unbinding
CVSS 6.5
CVE-2026-36605 MEDIUM
Mercusys AC12G (EU) V1 Firmware AC12G(EU)_V1_200909 - Denial of Service via Crafted Incomplete HTTP Requests
CVSS 6.5
CVE-2026-10705 LOW
dask HLL hyperloglog.py nunique_approx resource consumption
CVSS 3.1
CVE-2026-10692 MEDIUM
johnhuang316 code-index-mcp search_code_advanced is_safe_regex_pattern redos
CVSS 4.3
Details
Vulnerabilities 3,094
Exploit Likelihood High