CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,094 vulnerabilities with CWE-400
CVE-2026-39396 LOW
OpenBao has Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)
CVSS 3.1
CVE-2026-39320 HIGH
Signal K Server <2.25.0 WebSocket Subscriptions - Regular Expression Denial of Service
CVSS 7.5
CVE-2026-6060 MEDIUM
OTRS 7.0.x-8.0.x, 2023.x-2025.x, <2026.3.x - Denial of Service via SQL Box Resource Consumption
CVSS 4.5
CVE-2026-6607 MEDIUM
lm-sys fastchat Worker API Endpoint api_generate resource consumption
CVSS 5.3
CVE-2026-6601 MEDIUM
Lagom WHMCS Template Datatables resource consumption
CVSS 4.3
CVE-2026-40347 MEDIUM
Python-Multipart affected by Denial of Service via large multipart preamble or epilogue data
CVSS 5.3
CVE-2026-40481 HIGH
monetr: Unauthenticated Stripe webhook reads attacker-sized request bodies before signature validation
CVE-2026-40303 HIGH
zrok allows unauthenticated DoS via unbounded memory allocation in striped session cookie parsing
CVSS 7.5
CVE-2026-40192 HIGH
Pillow is vulnerable to a FITS GZIP decompression bomb
CVSS 7.5
CVE-2026-3505 HIGH
Unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion.
CVE-2026-35034 MEDIUM
Jellyfin: Potential Application DoS from excessively large SyncPlay group names
CVSS 6.5
CVE-2026-27308 LOW
ColdFusion | Uncontrolled Resource Consumption (CWE-400)
CVSS 2.4
CVE-2026-27307 LOW
ColdFusion | Uncontrolled Resource Consumption (CWE-400)
CVSS 2.4
CVE-2026-33116 HIGH
.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
CVSS 7.5
CVE-2026-26171 HIGH
Microsoft .NET and PowerShell - Resource Consumption Denial of Service
CVSS 7.5
CVE-2026-2405 MEDIUM
Schneider Electric PowerChute Serial Shutdown < 1.5 - Denial of Service via Excessive POST /helpabout Requests
CVSS 6.5
CVE-2026-30998 HIGH
FFmpeg < 8.0.1 - Denial of Service via Crafted Input File in zmqsend.c
CVSS 7.5
CVE-2026-39304 HIGH
Apache ActiveMQ TLSv1.3 KeyUpdate - Memory Exhaustion Denial of Service
CVSS 7.5
CVE-2026-5986 MEDIUM
Zod jsVideoUrlParser util.js getTime redos
CVSS 5.3
CVE-2026-23869 HIGH
React Server Components 19.0.0-19.0.4 19.1.0-19.1.5 19.2.0-19.2.4 - Denial of Service via Crafted HTTP Requests
CVSS 7.5
CVE-2026-34166 LOW
LiquidJS <10.25.3 replace Filter - Memory Limit Bypass
CVSS 3.7
CVE-2026-33459 MEDIUM
Uncontrolled Resource Consumption in Kibana Leading to Denial of Service
CVSS 6.5
CVE-2026-39865 MEDIUM
Axios HTTP/2 Session Cleanup State Corruption Vulnerability
CVSS 5.9
CVE-2026-35406 MEDIUM
Aardvark-dns has incorrect error handling for malformed tcp packets
CVSS 6.2
CVE-2026-34045 HIGH
Podman Desktop WebView Server Exposed
CVSS 8.2
Details
Vulnerabilities 3,094
Exploit Likelihood High