CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,367 vulnerabilities with CWE-400
CVE-2026-9171 HIGH
Vulnerabilities in IBM WebSphere Application affects IBM PowerVM Novalink.
CVSS 7.5
CVE-2026-47183 MEDIUM
Zeroconf: Unbounded exception-dedup state retains packet buffers via traceback frame locals, enabling LAN-local memory exhaustion
CVSS 6.5
CVE-2026-9602 MEDIUM
Mattermost Desktop App crashes when malformed arguments are provided to some exposed IPC methods
CVSS 6.5
CVE-2026-54340 HIGH
h2o has HTTP/2 state amplification
CVSS 7.5
CVE-2026-33754 MEDIUM
Wazuh: Unauthenticated cluster packet length leads to uncontrolled memory allocation (remote DoS)
CVSS 6.5
CVE-2026-44435 HIGH
Quicly: Remote Denial of Service via assertion failure when CRYPTO stream handshake data exceeds 32KB
CVSS 7.5
CVE-2026-44433 MEDIUM
Quicly is vulnerable to memory exhaustion
CVSS 5.3
CVE-2026-44019 HIGH
Docling Core has insufficient validation of image reference URIs
CVSS 8.1
CVE-2026-55407 MEDIUM
Buffa: Memory Exhaustion Denial of Service in decode_unknown_field via Unbounded Allocation
CVE-2026-55440 MEDIUM
Microsoft UFO: COMMAND_RESULTS handler creates unowned sessions, allowing authenticated session-squatting denial of service
CVSS 6.5
CVE-2026-52890 HIGH
Wekan: Arbitrary file read and server DoS via attachment versions.original.path
CVSS 7.1
CVE-2026-36590 HIGH
NanoMQ 0.24.9 - Denial of Service via nni_qos_db_set Function in broker_tcp.c
CVSS 7.5
CVE-2026-55399 MEDIUM
Absolute Secure Access < 14.55 Publisher - Credentialed Denial of Service
CVSS 4.3
CVE-2026-55398 LOW
Absolute Secure Access < 14.55 Tunnel Protocol - Server Denial of Service
CVSS 3.7
CVE-2026-33445 MEDIUM
Absolute Secure Access < 14.55 Server - Persistent Denial of Service
CVSS 5.9
CVE-2026-33444 LOW
Absolute Secure Access < 14.55 Server - Non-Persistent Denial of Service
CVSS 3.7
CVE-2026-33443 MEDIUM
Memory management error in Secure Access servers prior to 14.55
CVSS 5.9
CVE-2026-48357 MEDIUM
CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)
CVSS 6.2
CVE-2026-46627 MEDIUM
Twig: Sandbox resource exhaustion via unbounded `for` / `range()`
CVSS 6.5
CVE-2026-49477 HIGH
Soup Sieve: Regular Expression Denial of Service (ReDoS) in soupsieve Selector Parser
CVSS 7.5
CVE-2026-49476 HIGH
Soup Sieve: Memory Exhaustion via Large Comma-Separated Selector Lists in soupsieve
CVSS 7.5
CVE-2026-48125 MEDIUM
UAParser.js: Unbounded `Sec-CH-UA-Model` parsing can trigger ReDoS in `withClientHints()`
CVSS 5.3
CVE-2026-47736 HIGH
Puma PROXY Protocol v1 Parser Allows Remote Memory Exhaustion
CVSS 7.5
CVE-2026-47479 HIGH
Nvidia Triton Inference Server < 26.04 - Uncontrolled Resource Consumption
CVSS 7.5
CVE-2026-47476 HIGH
Nvidia Triton Inference Server < 26.04 - Uncontrolled Resource Consumption
CVSS 7.5
Details
Vulnerabilities 3,367
Exploit Likelihood High