CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,369 vulnerabilities with CWE-400
CVE-2026-2891 HIGH
Poly Voice Devices (CCX, Trio, Edge E) – Potential Denial of Service
CVE-2026-57962 MEDIUM
Denial-of-service via malicious LDAP address-book server
CVSS 5.3
CVE-2026-52197 HIGH
UTT nv518G nv518GV3v3.2.7-210919-161313 - Denial of Service via gohead/sub_44af70
CVSS 7.5
CVE-2026-57204 MEDIUM
pypdf: Missing stream length values ignore defined limits
CVSS 6.5
CVE-2026-9002 MEDIUM
IBM WebSphere eXtremes Scale is affected by uncontrolled resource consumption when XDF is enabled
CVSS 6.5
CVE-2026-57081 HIGH
Net::BitTorrent <= 2.0.1 - Bencode Memory Exhaustion
CVSS 7.5
CVE-2026-57080 HIGH
Net::BitTorrent <= 2.0.1 - Peer-Wire Message Length Memory Exhaustion
CVSS 7.5
CVE-2026-50750 HIGH
Apache ActiveMQ 5.19.7 and 6.2.6 - Unauthenticated OpenWire Denial of Service
CVSS 7.5
CVE-2026-13149 HIGH
Juliangruber Brace-expansion < 5.0.6 - Uncontrolled Resource Consumption
CVE-2026-45822 MEDIUM
Samverschueren Decode-uri-component < 0.5.0 - Uncontrolled Resource Consumption
CVE-2026-56018 HIGH
JavaScript::Minifier::XS versions before 0.16 for Perl leak memory on every call to minify(), allowing unbounded memory growth
CVSS 7.5
CVE-2026-36478 HIGH
Technitium DNS Server < 14.3 - Denial of Service via DnsServerApp.exe
CVSS 7.5
CVE-2026-47214 HIGH
Docling: Unsafe URI and Path Handling in HTML Backend
CVSS 7.1
CVE-2026-30041 HIGH
FastStone Image Viewer 8.3 - Integer Overflow and Denial of Service via PSD Parser
CVSS 7.5
CVE-2026-57914 MEDIUM
Apache Kerby: StackOverflow on parsing deeply nested ASN1 structures
CVSS 6.5
CVE-2026-48619 HIGH
Node - Uncontrolled Resource Consumption
CVSS 7.5
CVE-2026-38640 HIGH
relibc - Denial of Service via Crafted String in __assert_fail
CVSS 7.5
CVE-2026-38637 HIGH
relibc - Denial of Service via pthread_rwlockattr_setpshared()
CVSS 7.5
CVE-2026-54092 MEDIUM
File Browser: DoS Vulnerability on Public Login API
CVSS 6.5
CVE-2026-42005 MEDIUM
PowerDNS Authoritative - Insufficient Input Validation of Internal Web Server
CVSS 4.3
CVE-2026-52814 MEDIUM
Gogs: Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion)
CVE-2026-33235 HIGH
AutoGPT: Denial of Service (DoS) via Resource Exhaustion in text templating features
CVSS 7.7
CVE-2026-49851 HIGH
Mistune: Potential DoS via quadratic-time parsing in parse_link_text
CVSS 7.5
CVE-2026-50193 HIGH
jackson-databind: Deeply nested JsonNode throws StackOverflowError for toString()
CVSS 7.5
CVE-2026-55450 CRITICAL
Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak
CVSS 9.3
Details
Vulnerabilities 3,369
Exploit Likelihood High