CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,369 vulnerabilities with CWE-400
CVE-2026-51535 HIGH
OpENer 2.3.0 - Denial of Service via Network Processing Loop Resource Exhaustion
CVSS 7.5
CVE-2026-59936 HIGH
pypdf: Possible infinite loop for not terminated inline images
CVSS 7.5
CVE-2026-58210 HIGH
NATS Server: MQTT partial CONNECT packets can exhaust pre-auth memory
CVSS 7.5
CVE-2026-59937 HIGH
pypdf: Possible long runtimes for repeated malformed cross-reference entries
CVSS 7.5
CVE-2026-59879 HIGH
Immutable.js `List` 32-bit trie overflow → unrecoverable DoS
CVSS 7.5
CVE-2026-55646 MEDIUM
vLLM speech-to-text endpoints allocate full upload before enforcing the audio file-size limit
CVSS 6.5
CVE-2026-40140 HIGH
BeyondTrust Remote Support and PRA - Unauthenticated Denial of Service
CVSS 7.5
CVE-2026-58203 MEDIUM
NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size
CVSS 5.3
CVE-2026-9165 HIGH
Stackrox: stackrox: unbounded graphql query depth allows authenticated denial of service
CVSS 7.7
CVE-2026-24012 HIGH
Apache IoTDB: Denial of Service via Resource Exhaustion in Aggregation Query
CVSS 7.5
CVE-2026-14684 LOW
HdrHistogram AbstractHistogram.java memory allocation
CVSS 3.3
CVE-2026-14683 LOW
HdrHistogram AbstractHistogram.java memory allocation
CVSS 3.3
CVE-2026-26307 HIGH
Gitea git grep search lacks a timeout
CVSS 7.5
CVE-2026-52192 HIGH
UTT nv518G 3.2.7-210919-161313 - Remote Denial of Service via gohead/sub_445C5C Component
CVSS 7.5
CVE-2026-54886 MEDIUM
SSH SFTP server denial of service via extended channel data infinite loop
CVSS 4.3
CVE-2026-9563 HIGH
Eclipse Parsson < 1.1.7 - Uncontrolled Resource Consumption
CVSS 7.5
CVE-2026-54712 MEDIUM
OpenTelemetry Javaagent RMI context propagation allows resource exhaustion
CVSS 5.3
CVE-2026-54260 MEDIUM
Wagtail: Denial of service via unbounded filter specs in the image preview
CVSS 4.3
CVE-2026-54786 MEDIUM
Wasmtime: Leak in WASIp1 `fd_renumber` implementation
CVSS 5.0
CVE-2026-55595 MEDIUM
ImageMagick: Infinite Loop in connected-components when providing invalid arguments
CVSS 4.7
CVE-2026-55594 MEDIUM
ImageMagick: Stack Overflow in MVG decoder due to missing depth check.
CVSS 5.3
CVE-2026-47262 MEDIUM
containerd image-triggered runtime DoS via unbounded group parsing
CVSS 5.5
CVE-2026-54428 HIGH
Apache HttpComponents Core: HPackDecoder Unlimited Header List Size Before SETTINGS ACK
CVSS 7.5
CVE-2026-49090 MEDIUM
Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
CVSS 6.5
CVE-2026-54399 HIGH
Apache HttpComponents Core: Unbounded HTTP Header/Line Length in Default Configuration
CVSS 7.5
Details
Vulnerabilities 3,369
Exploit Likelihood High