CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,094 vulnerabilities with CWE-400
CVE-2026-42001 HIGH
PowerDNS Authoritative 4.9.0-4.9.14 and 5.0.0-5.0.4 - Denial of Service via Autoprimary SOA Query Validation
CVSS 7.5
CVE-2026-9137 HIGH
CSP Report Endpoint Log Flooding via Incorrect Size Limit
CVSS 7.5
CVE-2026-45498 MEDIUM KEV
Microsoft Defender Denial of Service Vulnerability
CVSS 4.0
CVE-2026-24215 MEDIUM
NVIDIA Triton Inference Server < 26.03 - Uncontrolled Resource Consumption in DALI Backend
CVSS 5.7
CVE-2026-8968 HIGH
Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component
CVSS 7.5
CVE-2026-33232 HIGH
AutoGPT: Unauthenticated DoS via Disk Space Exhaustion
CVSS 7.5
CVE-2026-8769 MEDIUM
vercel ai provider-utils response-handler.ts createJsonErrorResponseHandler resource consumption
CVSS 4.3
CVE-2026-38728 HIGH
Nodemailer smtp_server <3.18.3 - DoS
CVSS 7.5
CVE-2026-42304 HIGH
Twisted: Denial of Service (DoS) in twisted.names via Crafted DNS Compression Pointer Chains
CVSS 7.5
CVE-2026-33378 MEDIUM
Grafana Data Source Plugin: DoS (OOM) via Negative Interval Injection in $__timeGroup Macro
CVSS 6.5
CVE-2026-44248 MEDIUM
Netty: Resource exhaustion in MqttDecoder
CVSS 5.3
CVE-2026-42587 HIGH
Netty < 4.1.133.Final/4.2.13.Final HttpContentDecompressor - Decompression Bomb Denial of Service
CVSS 7.5
CVE-2026-42583 HIGH
Netty: Lz4FrameDecoder resource exhaustion
CVSS 7.5
CVE-2026-42579 HIGH
Netty: DNS Codec Input Validation Bypass in Netty (Encoder + Decoder)
CVSS 7.5
CVE-2026-44456 MEDIUM
Hono: bodyLimit() can be bypassed for chunked / unknown-length requests
CVSS 6.5
CVE-2026-44296 HIGH
Deskflow: TLS multiplexer DoS on failed `SSL_accept`
CVSS 7.5
CVE-2026-44242 LOW
Micronaut Framework: Unbounded bundleCache in ResourceBundleMessageSource Allows Memory Exhaustion via Accept-Language Header
CVSS 3.7
CVE-2026-44241 HIGH
Micronaut Framework: Unbounded formattersCache in TimeConverterRegistrar Allows Memory Exhaustion via Accept-Language Header
CVSS 7.5
CVE-2026-42544 HIGH
Granian: Unauthenticated DoS via WebSocket subprotocol header panic
CVSS 7.5
CVE-2026-44240 HIGH
basic-ftp allows a malicious FTP server to cause client-side denial of service via unbounded multiline control response buffering
CVSS 7.5
CVE-2026-34678 MEDIUM
CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)
CVSS 6.2
CVE-2026-34677 MEDIUM
CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)
CVSS 6.2
CVE-2026-34673 MEDIUM
CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)
CVSS 6.2
CVE-2026-34665 HIGH
CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)
CVSS 7.5
CVE-2026-34651 HIGH
Adobe Commerce | Uncontrolled Resource Consumption (CWE-400)
CVSS 7.5
Details
Vulnerabilities 3,094
Exploit Likelihood High