CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,367 vulnerabilities with CWE-400
CVE-2026-58627 HIGH
Microsoft Windows 10 Version 1607 - Windows DHCP Server Denial of Service Vulnerability
CVSS 7.5
CVE-2026-45756 HIGH
Symfony: JsonPath Evaluates Attacker-Controlled Regular Expressions in match()/search() Without Limits — ReDoS
CVSS 7.5
CVE-2026-59886 HIGH
pyasn1: Uncontrolled resource consumption when converting decoded REAL values
CVSS 7.5
CVE-2026-59885 HIGH
pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of service
CVSS 7.5
CVE-2026-59884 HIGH
pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs
CVSS 7.5
CVE-2026-59200 HIGH
Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()
CVSS 7.5
CVE-2026-50653 HIGH
Azure Active Directory Denial of Service Vulnerability
CVSS 7.5
CVE-2026-49799 MEDIUM
Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
CVSS 6.5
CVE-2026-12523 HIGH
Resource exhaustion in quiche HTTP/3 and QPACK layers
CVSS 7.5
CVE-2026-58486 HIGH
HedgeDoc: Denial-of-service via YAML alias expansion in note frontmatter
CVE-2026-51539 HIGH
libmodbus 3.1.12 - Denial of Service via Improper Timeout Management in Receive Loop
CVSS 7.5
CVE-2026-10668 LOW
Host-triggerable control-endpoint wedge (DoS) in Nuvoton NuMaker HSUSBD UDC driver
CVSS 2.4
CVE-2026-59161 HIGH
Excelize: Streaming GetRows row-bound bypass causes attacker-controlled allocation
CVSS 7.5
CVE-2026-55782 LOW
NanaZip: Unbounded memory allocation (DoS) in NanaZip WebAssembly parser via attacker-controlled section/name length fields
CVE-2026-55781 LOW
NanaZip: Unbounded memory allocation (DoS) in NanaZip UFS parser via unvalidated fs_bsize/fs_fsize superblock fields
CVE-2026-55780 LOW
NanaZip: Uncaught exception / unbounded allocation in NanaZip .NET single-file Extract() via unvalidated entry Size
CVE-2026-39244 HIGH
adm-zip < 0.5.18 - Denial of Service via Crafted ZIP Uncompressed Size Header
CVSS 7.5
CVE-2026-8609 MEDIUM
Pre-authentication denial of service via the OAuth login route
CVSS 5.3
CVE-2026-33382 HIGH
Grafana OSS - Denial of Service via Unbounded Request Body Size
CVSS 7.5
CVE-2026-40007 HIGH
Apache IoTDB: Unauthenticated unbounded recursion in IoTDB AirGap receiver's E-language prefix parser causes per-connection StackOverflowError
CVSS 7.5
CVE-2026-51600 HIGH
Tenda CP3 V31.1.9.91 - Unauthenticated Denial of Service via RTSP Content-Length Header Parsing
CVSS 7.5
CVE-2026-15308 HIGH
Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations
CVSS 7.5
CVE-2026-54772 HIGH
CoreWCF: Pre-authentication infinite-loop CPU exhaustion in CoreWCF net.tcp / net.pipe / net.uds framing handshake
CVSS 7.5
CVE-2026-51535 HIGH
OpENer 2.3.0 - Denial of Service via Network Processing Loop Resource Exhaustion
CVSS 7.5
CVE-2026-59936 HIGH
pypdf: Possible infinite loop for not terminated inline images
CVSS 7.5
Details
Vulnerabilities 3,367
Exploit Likelihood High