CWE-400
High likelihoodUncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
3,369 vulnerabilities with CWE-400
CVE-2026-51535
HIGH
OpENer 2.3.0 - Denial of Service via Network Processing Loop Resource Exhaustion
CVSS 7.5
CVE-2026-59936
HIGH
pypdf: Possible infinite loop for not terminated inline images
CVSS 7.5
CVE-2026-58210
HIGH
NATS Server: MQTT partial CONNECT packets can exhaust pre-auth memory
CVSS 7.5
CVE-2026-59937
HIGH
pypdf: Possible long runtimes for repeated malformed cross-reference entries
CVSS 7.5
CVE-2026-59879
HIGH
Immutable.js `List` 32-bit trie overflow → unrecoverable DoS
CVSS 7.5
CVE-2026-55646
MEDIUM
vLLM speech-to-text endpoints allocate full upload before enforcing the audio file-size limit
CVSS 6.5
CVE-2026-40140
HIGH
BeyondTrust Remote Support and PRA - Unauthenticated Denial of Service
CVSS 7.5
CVE-2026-58203
MEDIUM
NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size
CVSS 5.3
CVE-2026-9165
HIGH
Stackrox: stackrox: unbounded graphql query depth allows authenticated denial of service
CVSS 7.7
CVE-2026-24012
HIGH
Apache IoTDB: Denial of Service via Resource Exhaustion in Aggregation Query
CVSS 7.5
CVE-2026-14684
LOW
HdrHistogram AbstractHistogram.java memory allocation
CVSS 3.3
CVE-2026-14683
LOW
HdrHistogram AbstractHistogram.java memory allocation
CVSS 3.3
CVE-2026-26307
HIGH
Gitea git grep search lacks a timeout
CVSS 7.5
CVE-2026-52192
HIGH
UTT nv518G 3.2.7-210919-161313 - Remote Denial of Service via gohead/sub_445C5C Component
CVSS 7.5
CVE-2026-54886
MEDIUM
SSH SFTP server denial of service via extended channel data infinite loop
CVSS 4.3
CVE-2026-9563
HIGH
Eclipse Parsson < 1.1.7 - Uncontrolled Resource Consumption
CVSS 7.5
CVE-2026-54712
MEDIUM
OpenTelemetry Javaagent RMI context propagation allows resource exhaustion
CVSS 5.3
CVE-2026-54260
MEDIUM
Wagtail: Denial of service via unbounded filter specs in the image preview
CVSS 4.3
CVE-2026-54786
MEDIUM
Wasmtime: Leak in WASIp1 `fd_renumber` implementation
CVSS 5.0
CVE-2026-55595
MEDIUM
ImageMagick: Infinite Loop in connected-components when providing invalid arguments
CVSS 4.7
CVE-2026-55594
MEDIUM
ImageMagick: Stack Overflow in MVG decoder due to missing depth check.
CVSS 5.3
CVE-2026-47262
MEDIUM
containerd image-triggered runtime DoS via unbounded group parsing
CVSS 5.5
CVE-2026-54428
HIGH
Apache HttpComponents Core: HPackDecoder Unlimited Header List Size Before SETTINGS ACK
CVSS 7.5
CVE-2026-49090
MEDIUM
Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
CVSS 6.5
CVE-2026-54399
HIGH
Apache HttpComponents Core: Unbounded HTTP Header/Line Length in Default Configuration
CVSS 7.5
Details
Vulnerabilities
3,369
Exploit Likelihood
High