CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,371 vulnerabilities with CWE-400
CVE-2026-5316 MEDIUM
Nothings stb stb_vorbis.c setup_free allocation of resources
CVSS 4.3
CVE-2026-22815 HIGH
AIOHTTP: Uncapped memory usage possible through aiohttp allowing unlimited trailer headers
CVSS 7.5
CVE-2026-34445 HIGH
ONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings.
CVSS 8.6
CVE-2026-34404 HIGH
Nuxt OG Image vulnerable to DoS via image generation
CVSS 7.5
CVE-2026-34043 MEDIUM
Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects
CVSS 5.9
CVE-2026-33750 MEDIUM
brace-expansion: Zero-step sequence causes process hang and memory exhaustion
CVSS 6.5
CVE-2026-28375 MEDIUM
Grafana Testdata datasource can issue unbounded memory allocations
CVSS 6.5
CVE-2026-27879 MEDIUM
Query resampling can cause unbounded memory allocations
CVSS 6.5
CVE-2026-27859 MEDIUM
OX Dovecot Pro < 2.4.0, < 3.0.2, < 3.1.0 - Uncontrolled Resource Consumption via RFC 2231 MIME Parameters
CVSS 5.3
CVE-2026-27858 HIGH
OX Dovecot Pro < 2.3.0, < 3.1.0, < 2.4.0 - Unauthenticated Denial of Service via Managesieve Memory Allocation
CVSS 7.5
CVE-2026-27857 MEDIUM
OX Dovecot Pro < 2.3.0 - Denial of Service via NOOP Command Memory Exhaustion
CVSS 4.3
CVE-2026-33623 MEDIUM
PinchTab: OS Command Injection via Profile Name in Windows Cleanup Routine Enables Arbitrary Command Execution
CVSS 6.7
CVE-2026-33541 MEDIUM
TSPortal's Uncontrolled User Creation via Validation Side Effects Leads to Potential Denial of Service
CVSS 6.5
CVE-2026-33375 MEDIUM
Grafana MSSQL Data Source Plugin: Restriction Bypass Leading to OOM DoS
CVSS 6.5
CVE-2026-4926 HIGH
path-to-regexp vulnerable to Denial of Service via sequential optional groups
CVSS 7.5
CVE-2026-3116 MEDIUM
Improper Input Validation in Zoom Plugin Webhook Handler
CVSS 4.9
CVE-2026-33287 HIGH
LiquidJS has Exponential Memory Amplification through its replace_first Filter $& Pattern
CVSS 7.5
CVE-2026-33285 HIGH
LiquidJS: memoryLimit Bypass through Negative Range Values Leads to Process Crash
CVSS 7.5
CVE-2026-26233 MEDIUM
Denial of Service via HTTP/2 single packet attack on login endpoint
CVSS 4.3
CVE-2026-20084 HIGH
Cisco IOS XE Software 16.6.1-16.6.10, 16.7.1 - Unauthenticated Denial of Service via BOOTP Packet Handling
CVSS 8.6
CVE-2026-33268 MEDIUM
Nanoleaf Lines unauthenticated firmware file store
CVSS 6.5
CVE-2026-28874 HIGH
iOS and iPadOS < 26.4 - Denial of Service
CVSS 7.5
CVE-2026-33538 HIGH
Parse Server: Denial of service via unindexed database query for unconfigured auth providers
CVSS 7.5
CVE-2026-33474 MEDIUM
Vikunja Affected by DoS via Image Preview Generation
CVSS 6.5
CVE-2026-30662 MEDIUM
ConcreteCMS 9.4.7 - Authenticated Denial of Service via File Manager Bulk Download
CVSS 6.5
Details
Vulnerabilities 3,371
Exploit Likelihood High