CWE-400
High likelihoodUncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
3,094 vulnerabilities with CWE-400
CVE-2026-39396
LOW
OpenBao has Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)
CVSS 3.1
CVE-2026-39320
HIGH
Signal K Server <2.25.0 WebSocket Subscriptions - Regular Expression Denial of Service
CVSS 7.5
CVE-2026-6060
MEDIUM
OTRS 7.0.x-8.0.x, 2023.x-2025.x, <2026.3.x - Denial of Service via SQL Box Resource Consumption
CVSS 4.5
CVE-2026-6607
MEDIUM
lm-sys fastchat Worker API Endpoint api_generate resource consumption
CVSS 5.3
CVE-2026-6601
MEDIUM
Lagom WHMCS Template Datatables resource consumption
CVSS 4.3
CVE-2026-40347
MEDIUM
Python-Multipart affected by Denial of Service via large multipart preamble or epilogue data
CVSS 5.3
CVE-2026-40481
HIGH
monetr: Unauthenticated Stripe webhook reads attacker-sized request bodies before signature validation
CVE-2026-40303
HIGH
zrok allows unauthenticated DoS via unbounded memory allocation in striped session cookie parsing
CVSS 7.5
CVE-2026-40192
HIGH
Pillow is vulnerable to a FITS GZIP decompression bomb
CVSS 7.5
CVE-2026-3505
HIGH
Unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion.
CVE-2026-35034
MEDIUM
Jellyfin: Potential Application DoS from excessively large SyncPlay group names
CVSS 6.5
CVE-2026-27308
LOW
ColdFusion | Uncontrolled Resource Consumption (CWE-400)
CVSS 2.4
CVE-2026-27307
LOW
ColdFusion | Uncontrolled Resource Consumption (CWE-400)
CVSS 2.4
CVE-2026-33116
HIGH
.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
CVSS 7.5
CVE-2026-26171
HIGH
Microsoft .NET and PowerShell - Resource Consumption Denial of Service
CVSS 7.5
CVE-2026-2405
MEDIUM
Schneider Electric PowerChute Serial Shutdown < 1.5 - Denial of Service via Excessive POST /helpabout Requests
CVSS 6.5
CVE-2026-30998
HIGH
FFmpeg < 8.0.1 - Denial of Service via Crafted Input File in zmqsend.c
CVSS 7.5
CVE-2026-39304
HIGH
Apache ActiveMQ TLSv1.3 KeyUpdate - Memory Exhaustion Denial of Service
CVSS 7.5
CVE-2026-5986
MEDIUM
Zod jsVideoUrlParser util.js getTime redos
CVSS 5.3
CVE-2026-23869
HIGH
React Server Components 19.0.0-19.0.4 19.1.0-19.1.5 19.2.0-19.2.4 - Denial of Service via Crafted HTTP Requests
CVSS 7.5
CVE-2026-34166
LOW
LiquidJS <10.25.3 replace Filter - Memory Limit Bypass
CVSS 3.7
CVE-2026-33459
MEDIUM
Uncontrolled Resource Consumption in Kibana Leading to Denial of Service
CVSS 6.5
CVE-2026-39865
MEDIUM
Axios HTTP/2 Session Cleanup State Corruption Vulnerability
CVSS 5.9
CVE-2026-35406
MEDIUM
Aardvark-dns has incorrect error handling for malformed tcp packets
CVSS 6.2
CVE-2026-34045
HIGH
Podman Desktop WebView Server Exposed
CVSS 8.2
Details
Vulnerabilities
3,094
Exploit Likelihood
High