CWE-400
High likelihoodUncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
2,909 vulnerabilities with CWE-400
CVE-2026-40481
HIGH
monetr: Unauthenticated Stripe webhook reads attacker-sized request bodies before signature validation
CVE-2026-40303
HIGH
zrok allows unauthenticated DoS via unbounded memory allocation in striped session cookie parsing
CVSS 7.5
CVE-2026-40192
HIGH
Pillow is vulnerable to a FITS GZIP decompression bomb
CVSS 7.5
CVE-2026-3505
HIGH
Unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion.
CVE-2026-35034
MEDIUM
Jellyfin: Potential Application DoS from excessively large SyncPlay group names
CVSS 6.5
CVE-2026-27308
LOW
ColdFusion | Uncontrolled Resource Consumption (CWE-400)
CVSS 2.4
CVE-2026-27307
LOW
ColdFusion | Uncontrolled Resource Consumption (CWE-400)
CVSS 2.4
CVE-2026-33116
HIGH
.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
CVSS 7.5
CVE-2026-26171
HIGH
.NET Denial of Service Vulnerability
CVSS 7.5
CVE-2026-2405
MEDIUM
Schneider Electric PowerChute™ Serial Shutdown - Denial of Service
CVSS 6.5
CVE-2026-30998
HIGH
FFmpeg 8.0.1 - DoS
CVSS 7.5
CVE-2026-39304
HIGH
Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Incorrect handling of TLSv1.3 KeyUpdate can be exploited to cause DoS via OOM
CVSS 7.5
CVE-2026-5986
MEDIUM
Zod jsVideoUrlParser util.js getTime redos
CVSS 5.3
CVE-2026-23869
HIGH
Meta React-server-dom-turbopack < 19.0.4 - Denial of Service
CVSS 7.5
CVE-2026-34166
LOW
LiquidJS has a Memory Limit Bypass via Quadratic Amplification in `replace` Filter
CVSS 3.7
CVE-2026-33459
MEDIUM
Uncontrolled Resource Consumption in Kibana Leading to Denial of Service
CVSS 6.5
CVE-2026-39865
MEDIUM
Axios HTTP/2 Session Cleanup State Corruption Vulnerability
CVSS 5.9
CVE-2026-35406
MEDIUM
Aardvark-dns has incorrect error handling for malformed tcp packets
CVSS 6.2
CVE-2026-34045
HIGH
Podman Desktop WebView Server Exposed
CVSS 8.2
CVE-2026-32588
MEDIUM
Apache Cassandra: Authenticated DoS via ALTER ROLE Password Hashing
CVSS 6.5
CVE-2026-35441
MEDIUM
Directus Affected by GraphQL Alias Amplification Denial-of-Service Due to Missing Query Cost/Complexity Limits
CVSS 6.5
CVE-2026-0049
MEDIUM
Google Android < 16-qpr2 - Denial of Service
CVSS 6.2
CVE-2026-34148
HIGH
Fedify affected by resource exhaustion caused by unbounded redirect following during remote key/document resolution
CVSS 7.5
CVE-2026-26477
MEDIUM
Dokuwiki 2025-05-14b - DoS
CVSS 4.3
CVE-2026-34827
HIGH
Rack: Algorithmic-Complexity DoS in Rack::Multipart::Parser
CVSS 7.5
Details
Vulnerabilities
2,909
Exploit Likelihood
High