CWE-400
High likelihoodUncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
3,367 vulnerabilities with CWE-400
CVE-2026-9171
HIGH
Vulnerabilities in IBM WebSphere Application affects IBM PowerVM Novalink.
CVSS 7.5
CVE-2026-47183
MEDIUM
Zeroconf: Unbounded exception-dedup state retains packet buffers via traceback frame locals, enabling LAN-local memory exhaustion
CVSS 6.5
CVE-2026-9602
MEDIUM
Mattermost Desktop App crashes when malformed arguments are provided to some exposed IPC methods
CVSS 6.5
CVE-2026-54340
HIGH
h2o has HTTP/2 state amplification
CVSS 7.5
CVE-2026-33754
MEDIUM
Wazuh: Unauthenticated cluster packet length leads to uncontrolled memory allocation (remote DoS)
CVSS 6.5
CVE-2026-44435
HIGH
Quicly: Remote Denial of Service via assertion failure when CRYPTO stream handshake data exceeds 32KB
CVSS 7.5
CVE-2026-44433
MEDIUM
Quicly is vulnerable to memory exhaustion
CVSS 5.3
CVE-2026-44019
HIGH
Docling Core has insufficient validation of image reference URIs
CVSS 8.1
CVE-2026-55407
MEDIUM
Buffa: Memory Exhaustion Denial of Service in decode_unknown_field via Unbounded Allocation
CVE-2026-55440
MEDIUM
Microsoft UFO: COMMAND_RESULTS handler creates unowned sessions, allowing authenticated session-squatting denial of service
CVSS 6.5
CVE-2026-52890
HIGH
Wekan: Arbitrary file read and server DoS via attachment versions.original.path
CVSS 7.1
CVE-2026-36590
HIGH
NanoMQ 0.24.9 - Denial of Service via nni_qos_db_set Function in broker_tcp.c
CVSS 7.5
CVE-2026-55399
MEDIUM
Absolute Secure Access < 14.55 Publisher - Credentialed Denial of Service
CVSS 4.3
CVE-2026-55398
LOW
Absolute Secure Access < 14.55 Tunnel Protocol - Server Denial of Service
CVSS 3.7
CVE-2026-33445
MEDIUM
Absolute Secure Access < 14.55 Server - Persistent Denial of Service
CVSS 5.9
CVE-2026-33444
LOW
Absolute Secure Access < 14.55 Server - Non-Persistent Denial of Service
CVSS 3.7
CVE-2026-33443
MEDIUM
Memory management error in Secure Access servers prior to 14.55
CVSS 5.9
CVE-2026-48357
MEDIUM
CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)
CVSS 6.2
CVE-2026-46627
MEDIUM
Twig: Sandbox resource exhaustion via unbounded `for` / `range()`
CVSS 6.5
CVE-2026-49477
HIGH
Soup Sieve: Regular Expression Denial of Service (ReDoS) in soupsieve Selector Parser
CVSS 7.5
CVE-2026-49476
HIGH
Soup Sieve: Memory Exhaustion via Large Comma-Separated Selector Lists in soupsieve
CVSS 7.5
CVE-2026-48125
MEDIUM
UAParser.js: Unbounded `Sec-CH-UA-Model` parsing can trigger ReDoS in `withClientHints()`
CVSS 5.3
CVE-2026-47736
HIGH
Puma PROXY Protocol v1 Parser Allows Remote Memory Exhaustion
CVSS 7.5
CVE-2026-47479
HIGH
Nvidia Triton Inference Server < 26.04 - Uncontrolled Resource Consumption
CVSS 7.5
CVE-2026-47476
HIGH
Nvidia Triton Inference Server < 26.04 - Uncontrolled Resource Consumption
CVSS 7.5
Details
Vulnerabilities
3,367
Exploit Likelihood
High