CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

2,909 vulnerabilities with CWE-400
CVE-2026-40481 HIGH
monetr: Unauthenticated Stripe webhook reads attacker-sized request bodies before signature validation
CVE-2026-40303 HIGH
zrok allows unauthenticated DoS via unbounded memory allocation in striped session cookie parsing
CVSS 7.5
CVE-2026-40192 HIGH
Pillow is vulnerable to a FITS GZIP decompression bomb
CVSS 7.5
CVE-2026-3505 HIGH
Unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion.
CVE-2026-35034 MEDIUM
Jellyfin: Potential Application DoS from excessively large SyncPlay group names
CVSS 6.5
CVE-2026-27308 LOW
ColdFusion | Uncontrolled Resource Consumption (CWE-400)
CVSS 2.4
CVE-2026-27307 LOW
ColdFusion | Uncontrolled Resource Consumption (CWE-400)
CVSS 2.4
CVE-2026-33116 HIGH
.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
CVSS 7.5
CVE-2026-26171 HIGH
.NET Denial of Service Vulnerability
CVSS 7.5
CVE-2026-2405 MEDIUM
Schneider Electric PowerChute™ Serial Shutdown - Denial of Service
CVSS 6.5
CVE-2026-30998 HIGH
FFmpeg 8.0.1 - DoS
CVSS 7.5
CVE-2026-39304 HIGH
Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Incorrect handling of TLSv1.3 KeyUpdate can be exploited to cause DoS via OOM
CVSS 7.5
CVE-2026-5986 MEDIUM
Zod jsVideoUrlParser util.js getTime redos
CVSS 5.3
CVE-2026-23869 HIGH
Meta React-server-dom-turbopack < 19.0.4 - Denial of Service
CVSS 7.5
CVE-2026-34166 LOW
LiquidJS has a Memory Limit Bypass via Quadratic Amplification in `replace` Filter
CVSS 3.7
CVE-2026-33459 MEDIUM
Uncontrolled Resource Consumption in Kibana Leading to Denial of Service
CVSS 6.5
CVE-2026-39865 MEDIUM
Axios HTTP/2 Session Cleanup State Corruption Vulnerability
CVSS 5.9
CVE-2026-35406 MEDIUM
Aardvark-dns has incorrect error handling for malformed tcp packets
CVSS 6.2
CVE-2026-34045 HIGH
Podman Desktop WebView Server Exposed
CVSS 8.2
CVE-2026-32588 MEDIUM
Apache Cassandra: Authenticated DoS via ALTER ROLE Password Hashing
CVSS 6.5
CVE-2026-35441 MEDIUM
Directus Affected by GraphQL Alias Amplification Denial-of-Service Due to Missing Query Cost/Complexity Limits
CVSS 6.5
CVE-2026-0049 MEDIUM
Google Android < 16-qpr2 - Denial of Service
CVSS 6.2
CVE-2026-34148 HIGH
Fedify affected by resource exhaustion caused by unbounded redirect following during remote key/document resolution
CVSS 7.5
CVE-2026-26477 MEDIUM
Dokuwiki 2025-05-14b - DoS
CVSS 4.3
CVE-2026-34827 HIGH
Rack: Algorithmic-Complexity DoS in Rack::Multipart::Parser
CVSS 7.5
Details
Vulnerabilities 2,909
Exploit Likelihood High