CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,371 vulnerabilities with CWE-400
CVE-2026-30653 HIGH
free5gc < 4.2.0 - Denial of Service via AMF HandleAuthenticationFailure
CVSS 7.5
CVE-2026-4727 HIGH
Denial-of-service in the Libraries component in NSS
CVSS 7.5
CVE-2026-4726 HIGH
Firefox and Thunderbird - Denial of Service in XML Component
CVSS 7.5
CVE-2026-4704 HIGH
Denial-of-service in the WebRTC: Signaling component
CVSS 7.5
CVE-2026-33176 HIGH
ActiveSupport < 8.1.2.1, < 8.0.4.1, < 7.2.3.1 - Denial of Service via BigDecimal Scientific Notation Expansion
CVSS 7.5
CVE-2026-33169 MEDIUM
Active Support <8.1.2.1/8.0.4.1/7.2.3.1 - DoS
CVSS 5.3
CVE-2026-4539 LOW
pygments archetype.py AdlLexer redos
CVSS 3.3
CVE-2026-33204 HIGH
SimpleJWT <1.1.1 PBES2 JWE Header - Denial of Service
CVSS 7.5
CVE-2026-33155 HIGH
DeepDiff has Memory Exhaustion DoS through SAFE_TO_IMPORT
CVSS 7.5
CVE-2026-33123 MEDIUM
pypdf has inefficient decoding of array-based streams
CVSS 6.5
CVE-2026-25667 HIGH
.NET 8.0.0-8.0.21 and 9.0.0-9.0.10 - Uncontrolled Resource Consumption via Crafted QUIC Packet
CVSS 7.5
CVE-2026-29856 HIGH
aaPanel 7.57.0 - Regular Expression Denial of Service in VirtualHost Configuration Parser
CVSS 7.5
CVE-2026-27980 HIGH
Next.js: Unbounded next/image disk cache growth can exhaust storage
CVSS 7.5
CVE-2026-25771 MEDIUM
Wazuh Vulnerable to Denial of Service via Synchronous I/O Blocking in Asynchronous Authentication Middleware
CVSS 5.3
CVE-2026-30405 HIGH
GoBGP gobgpd 4.2.0 - Denial of Service via NEXT_HOP Path Attribute
CVSS 7.5
CVE-2026-4174 LOW
Radare2 5.9.9 - Uncontrolled Resource Consumption in Mach-O File Parser
CVSS 3.3
CVE-2026-30955 MEDIUM
Gokapi < 2.2.4 - Authenticated Denial of Service via Unbounded Request Body
CVSS 6.5
CVE-2026-29776 LOW
FreeRDP <3.24.0 - Memory Corruption
CVSS 3.1
CVE-2026-25819 HIGH
HMS Networks Ewon Flexy <15.0s4 - DoS
CVSS 7.5
CVE-2026-23940 MEDIUM
hexpm < 495f01607d3eae4aed7ad09b2f54f31ec7a7df01 - Denial of Service via Oversized Package Upload
CVSS 6.5
CVE-2026-31958 HIGH
Tornado < 6.5.5 - Denial of Service via Multipart Form Data Parsing
CVSS 7.5
CVE-2026-30980 MEDIUM
iccdev < 2.3.1.5 - Denial of Service via Stack Overflow in CIccBasicStructFactory::CreateStruct()
CVSS 5.5
CVE-2026-26018 HIGH
CoreDNS < 1.14.2 - Denial of Service via Predictable PRNG in Loop Detection Plugin
CVSS 7.5
CVE-2026-29049 MEDIUM
melange < 0.40.5 - Server-Side Request Forgery via Unbounded URI Download
CVSS 4.3
CVE-2026-28789 HIGH
olivetin < 3000.10.3 - Unauthenticated Denial of Service via OAuth2 Login Concurrent Map Access
CVSS 7.5
Details
Vulnerabilities 3,371
Exploit Likelihood High