CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,371 vulnerabilities with CWE-400
CVE-2026-27308 LOW
ColdFusion | Uncontrolled Resource Consumption (CWE-400)
CVSS 2.4
CVE-2026-27307 LOW
ColdFusion | Uncontrolled Resource Consumption (CWE-400)
CVSS 2.4
CVE-2026-33116 HIGH
.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
CVSS 7.5
CVE-2026-26171 HIGH
Microsoft .NET and PowerShell - Resource Consumption Denial of Service
CVSS 7.5
CVE-2026-2405 MEDIUM
Schneider Electric PowerChute Serial Shutdown < 1.5 - Denial of Service via Excessive POST /helpabout Requests
CVSS 6.5
CVE-2026-30998 HIGH
FFmpeg < 8.0.1 - Denial of Service via Crafted Input File in zmqsend.c
CVSS 7.5
CVE-2026-39304 HIGH
Apache ActiveMQ TLSv1.3 KeyUpdate - Memory Exhaustion Denial of Service
CVSS 7.5
CVE-2026-5986 MEDIUM
Zod jsVideoUrlParser util.js getTime redos
CVSS 5.3
CVE-2026-23869 HIGH
React Server Components 19.0.0-19.0.4 19.1.0-19.1.5 19.2.0-19.2.4 - Denial of Service via Crafted HTTP Requests
CVSS 7.5
CVE-2026-34166 LOW
LiquidJS <10.25.3 replace Filter - Memory Limit Bypass
CVSS 3.7
CVE-2026-33459 MEDIUM
Uncontrolled Resource Consumption in Kibana Leading to Denial of Service
CVSS 6.5
CVE-2026-39865 MEDIUM
Axios HTTP/2 Session Cleanup State Corruption Vulnerability
CVSS 5.9
CVE-2026-35406 MEDIUM
Aardvark-dns has incorrect error handling for malformed tcp packets
CVSS 6.2
CVE-2026-34045 HIGH
Podman Desktop WebView Server Exposed
CVSS 8.2
CVE-2026-32588 MEDIUM
Apache Cassandra: Authenticated DoS via ALTER ROLE Password Hashing
CVSS 6.5
CVE-2026-35441 MEDIUM
Directus Affected by GraphQL Alias Amplification Denial-of-Service Due to Missing Query Cost/Complexity Limits
CVSS 6.5
CVE-2026-0049 MEDIUM
Android - Denial of Service via LocalImageResolver Header Decoding
CVSS 6.2
CVE-2026-34148 HIGH
Fedify affected by resource exhaustion caused by unbounded redirect following during remote key/document resolution
CVSS 7.5
CVE-2026-26477 MEDIUM
DokuWiki 2025-05-14b - Denial of Service via media_upload_xhr() Function
CVSS 4.3
CVE-2026-34827 HIGH
Rack: Algorithmic-Complexity DoS in Rack::Multipart::Parser
CVSS 7.5
CVE-2026-34593 HIGH
Ash Framework: Ash.Type.Module.cast_input/2 atom exhaustion via unchecked Module.concat allows BEAM VM crash
CVSS 7.5
CVE-2026-34829 HIGH
Rack: Denial of Service via Unbounded Multipart File Upload Without Content-Length
CVSS 7.5
CVE-2026-34826 MEDIUM
Rack: Unbounded Range Count in get_byte_ranges Enables DoS
CVSS 5.3
CVE-2026-34230 MEDIUM
Rack: Quadratic complexity in Rack::Utils.select_best_encoding via wildcard Accept-Encoding header
CVSS 5.3
CVE-2026-31935 HIGH
Suricata http2: unbounded resource consumption
CVSS 7.5
Details
Vulnerabilities 3,371
Exploit Likelihood High