CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,094 vulnerabilities with CWE-400
CVE-2026-10691 MEDIUM
wonderwhy-er DesktopCommanderMCP start_search search-manager.ts redos
CVSS 4.3
CVE-2026-10650 MEDIUM
warmcat libwebsockets SSH Protocol sshd.c lws_ssh_parse_plaintext resource consumption
CVSS 5.3
CVE-2026-42342 HIGH
React Router vulnerable to DoS via unbounded path expansion in __manifest endpoint
CVSS 7.5
CVE-2026-42073 MEDIUM
OpenClaude's MCP OAuth Callback: State Check Bypass via error Param Leads to DoS
CVSS 6.5
CVE-2026-45680 MEDIUM
OpenTelemetry eBPF Instrumentation: Unbounded BPF internal metrics replay can exhaust CPU
CVSS 5.9
CVE-2026-10291 MEDIUM
Enderfga claw-orchestrator <= 3.7.0 - Inefficient Regular Expression Complexity in Session Grep Endpoint
CVSS 4.3
CVE-2026-0074 MEDIUM
Android 14-16 LauncherProcessImageListener - Resource Exhaustion Denial of Service
CVSS 5.5
CVE-2026-0069 MEDIUM
ApkChecksums.java - Denial of Service via Resource Exhaustion in verifySignature
CVSS 5.5
CVE-2026-0042 MEDIUM
Android 14-16 UBSan Runtime - Resource Exhaustion Denial of Service
CVSS 5.5
CVE-2026-37234 HIGH
FlexRIC 2.0.0 - Resource Exhaustion via Stale Subscription State Leak
CVSS 8.2
CVE-2026-49361 HIGH
Apache Fluss Netty Frame Decoder Memory Exhaustion Vulnerability
CVSS 7.5
CVE-2026-10224 MEDIUM
NousResearch hermes-agent Webhook Endpoint feishu.py _handle_webhook_request resource consumption
CVSS 5.3
CVE-2026-48208 MEDIUM
OTRS - Denial-of-Service via SVG Rendering in Ticket
CVSS 6.5
CVE-2026-48187 MEDIUM
OTRS Email Handling - Resource Exhaustion Denial of Service
CVSS 5.7
CVE-2026-10156 MEDIUM
Open5GS nf-instances Endpoint nnrf-handler.c handle_amf_info resource consumption
CVSS 4.3
CVE-2026-46385 HIGH
iskorotkov/avro: CPU Exhaustion in Avro Decoder
CVE-2026-45149 MEDIUM
brace-expansion: Large numeric range defeats documented `max` DoS protection
CVSS 6.5
CVE-2026-10069 HIGH
Shibby Tomato miniupnpd resource consumption
CVSS 7.5
CVE-2026-49324 MEDIUM
Indian Scout Bobber 2025 WCM brute-force
CVSS 4.6
CVE-2026-49094 MEDIUM
Uncontrolled Resource Consumption in Kibana Leading to Denial of Service
CVSS 6.5
CVE-2026-46843 MEDIUM
Oracle Rest Data Services < 26.1.0 - Denial of Service
CVSS 5.3
CVE-2026-46835 HIGH
Oracle Database Server < 23.26.2 - Denial of Service
CVSS 7.5
CVE-2026-46834 HIGH
Oracle Database Server < 23.26.2 - Denial of Service
CVSS 7.5
CVE-2026-46829 HIGH
Oracle Rest Data Services < 26.1.0 - Denial of Service
CVSS 7.5
CVE-2026-46775 CRITICAL
Oracle REST Data Services 24.2.0-26.1.0 - Authenticated Remote Code Execution via HTTPS
CVSS 9.9
Details
Vulnerabilities 3,094
Exploit Likelihood High