CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,094 vulnerabilities with CWE-400
CVE-2026-42154 HIGH
Prometheus: remote read endpoint allows denial of service via crafted snappy payload
CVSS 7.5
CVE-2026-37459 HIGH
FRRouting stable/10.0-stable/10.6 - Denial of Service via Crafted BGP UPDATE Message
CVSS 7.5
CVE-2026-42467 HIGH
Open-SAE-J1939 through commit b6caf884df46435e539b1ecbf92b6c29b345bdfe - Denial of Service via Crafted CAN Frame
CVSS 7.5
CVE-2026-42403 HIGH
Apache Neethi: Circular Policy Reference Infinite Loop
CVSS 7.5
CVE-2026-42402 HIGH
Apache Neethi: Policy Normalization Unbounded Resource Allocation DoS
CVSS 7.5
CVE-2026-40951 MEDIUM
Memory corruption in Secure Access Windows clients prior to 14.50
CVSS 5.5
CVE-2026-36958 HIGH
U-SPEED N300 V1.0.0 - Denial of Service via Concurrent HTTP Requests
CVSS 7.5
CVE-2026-36957 HIGH
Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router V1.0.0 - DoS
CVSS 7.5
CVE-2026-28221 MEDIUM
Wazuh: Pre-auth stack-based buffer overflow in wazuh-remoted print_hex_string() due to signed char promotion on x86_64
CVSS 6.5
CVE-2026-22745 MEDIUM
CVE-2026-22745 : Denial of service in static resource handling on Windows platforms
CVSS 5.3
CVE-2026-22740 MEDIUM
Spring Framework DoS with Multipart Temp Files in WebFlux
CVSS 6.5
CVE-2026-40980 MEDIUM
Spring AI 1.0.0-1.0.5 - Memory Corruption
CVSS 6.5
CVE-2026-35901 MEDIUM
Mercury MIPC252W 1.0.5 Build 230306 Rel.79931n - Authenticated Denial of Service via RTSP SETUP Request Flood
CVSS 4.4
CVE-2026-30350 HIGH
Agent Protocol server e9a89f - Denial of Service via /store/items/search Endpoint
CVSS 7.5
CVE-2026-41680 HIGH
Marked: OOM Denial of Service via Infinite Recursion in marked Tokenizer
CVSS 7.5
CVE-2026-41324 HIGH
basic-ftp vulnerable to denial of service via unbounded memory consumption in Client.list()
CVSS 7.5
CVE-2026-41309 HIGH
Open Source Social Network (OSSN) Vulnerable to Resource Exhaustion via Malicious Image Processing
CVSS 8.2
CVE-2026-33610 MEDIUM
Possible file descriptor exhaustion in forward-dnsupdate
CVSS 5.9
CVE-2026-6844 MEDIUM
Binutils: binutils: denial of service vulnerabilities in readelf via crafted elf files
CVSS 5.5
CVE-2026-6022 HIGH
Uncontrolled Resource Consumption Vulnerability in Telerik UI for ASP.NET AJAX
CVSS 7.5
CVE-2026-6416 LOW
Tanium addressed an uncontrolled resource consumption vulnerability in Interact.
CVSS 2.7
CVE-2026-41146 HIGH
facil.io and downstream iodine ruby gem vulnerable to uncontrolled resource consumption and loop with unreachable exit condition
CVE-2026-41135 HIGH
free5GC PCF: Memory Leak via CORS Middleware Registration in HTTP Handler Leads to Denial of Service
CVSS 7.5
CVE-2026-6797 MEDIUM
Sanluan PublicCMS DocToHtmlUtils.java ZipSecureFile.setMinflateRatio resource consumption
CVSS 4.3
CVE-2026-40924 MEDIUM
Tekton Pipelines: HTTP Resolver Unbounded Response Body Read Enables Denial of Service via Memory Exhaustion
CVSS 6.5
Details
Vulnerabilities 3,094
Exploit Likelihood High