CWE-400— Uncontrolled Resource Consumption (Denial of Service)
The product does not properly control the allocation and maintenance of a limited resource.— MITRE CWE catalog
3,739 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-400page 66 of 75
- CVE-2026-25762HIGHCVSS 7.5EG 7.52026-02-06
AdonisJS is a TypeScript-first web framework. Prior to versions 10.1.3 and 11.0.0-next.9, a denial of service (DoS) vulnerability exists in the multipart file handling logic of @adonisjs/bodyparser. When processing file uploads, the multip…
- CVE-2026-25771HIGHCVSS 7.5EG 7.52026-03-17
Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.3.0 and prior to version 4.14.3, a Denial of Service (DoS) vulnerability exists in the Wazuh API authentication middleware …
- CVE-2026-25791HIGHCVSS 7.5EG 7.52026-02-09
Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to 1.7.0, the DNS C2 listener accepts unauthenticated TOTP bootstrap messages and allocates server-side DNS sessions without validating OTP values, even…
- CVE-2026-25819HIGHCVSS 7.5EG 7.52026-03-13
HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 allows unauthenticated attackers to cause a Denial of Service by using a specially crafted HTTP reque…
- CVE-2026-25949HIGHCVSS 7.5EG 7.52026-02-12
Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.8, there is a potential vulnerability in Traefik managing STARTTLS requests. An unauthenticated client can bypass Traefik entrypoint respondingTimeouts.readTimeout by sending…
- CVE-2026-26018HIGHCVSS 7.5EG 7.52026-03-06
CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a denial of service vulnerability exists in CoreDNS's loop detection plugin that allows an attacker to crash the DNS server by sending specially crafted DNS queries. The…
- CVE-2026-26047MEDIUMCVSS 6.5EG 6.52026-02-21
A denial-of-service vulnerability was identified in Moodle’s TeX formula editor. When rendering TeX content using mimetex, insufficient execution time limits could allow specially crafted formulas to consume excessive server resources. A…
- CVE-2026-26066MEDIUMCVSS 6.2EG 6.22026-02-24
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a crafted profile contain invalid IPTC data may cause an infinite loop when writing it with `IPTCTEXT`…
- CVE-2026-26171HIGHCVSS 7.5EG 7.52026-04-14
Uncontrolled resource consumption in .NET allows an unauthorized attacker to deny service over a network.
- CVE-2026-26233MEDIUMCVSS 6.5EG 6.52026-03-25
Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to rate limit login requests which allows unauthenticated remote attackers to cause denial of service (server crash and restart) via HTTP/2 …
- CVE-2026-26307HIGHCVSS 7.5EG 7.52026-07-03
Gitea versions before 1.25.5 do not enforce a timeout on git grep searches, allowing expensive searches to consume server resources.
- CVE-2026-26477HIGHCVSS 4.3EG 7.52026-04-03
An issue in Dokuwiki v.2025-05-14b "Librarian" [56.2] allows a remote attacker to cause a denial of service via the media_upload_xhr() function in the media.php file
- CVE-2026-26673HIGHCVSS 7.5EG 7.52026-03-04
An issue in DJI Mavic Mini, Spark, Mavic Air, Mini, Mini SE 0.1.00.0500 and below allows a remote attacker to cause a denial of service via the DJI Enhanced-WiFi transmission subsystem
- CVE-2026-26937HIGHCVSS 7.5EG 7.52026-02-26
Uncontrolled Resource Consumption (CWE-400) in the Timelion component in Kibana can lead Denial of Service via Input Data Manipulation (CAPEC-153)
- CVE-2026-26999HIGHCVSS 7.5EG 7.52026-03-05
Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.38 and 3.6.9, there is a potential vulnerability in Traefik managing TLS handshake on TCP routers. When Traefik processes a TLS connection on a TCP router, the read…
- CVE-2026-27204MEDIUMCVSS 6.5EG 6.52026-02-24
Wasmtime is a runtime for WebAssembly. Prior to versions 24.0.6, 36.0.6, 4.0.04, 41.0.4, and 42.0.0, Wasmtime's implementation of WASI host interfaces are susceptible to guest-controlled resource exhaustion on the host. Wasmtime did not ap…
- CVE-2026-27307LOWCVSS 2.4EG 2.42026-04-14
ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. A high-privileged attacker could exploit this vulnerability and exhaust sy…
- CVE-2026-27308LOWCVSS 2.4EG 2.42026-04-14
ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. A high-privileged attacker could exploit this vulnerability and exhaust sy…
- CVE-2026-27576MEDIUMCVSS 4.0EG 4.02026-02-21
OpenClaw is a personal AI assistant. In versions 2026.2.17 and below, the ACP bridge accepts very large prompt text blocks and can assemble oversized prompt payloads before forwarding them to chat.send. Because ACP runs over local stdio, t…
- CVE-2026-27630HIGHCVSS 7.5EG 7.52026-02-26
TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Versions prior to version 2.02 are vulnerable to a Denial of Service (DoS) attack known as Slowloris. The server spawns a new OS thread for every incoming connection withou…
- CVE-2026-27633HIGHCVSS 7.5EG 7.52026-02-26
TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Versions prior to version 2.02 have a Denial of Service (DoS) vulnerability via memory exhaustion. Unauthenticated remote attackers can send an HTTP POST request to the ser…
- CVE-2026-27857HIGHCVSS 7.5EG 7.52026-03-27
Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands will result in client disconnection. This 1 MB can be left allocated for longer time periods by not sending the command e…
- CVE-2026-27858HIGHCVSS 7.5EG 7.52026-03-27
Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access …
- CVE-2026-27859MEDIUMCVSS 5.3EG 5.32026-03-27
A mail message containing excessive amount of RFC 2231 MIME parameters causes LMTP to use too much CPU. A suitably formatted mail message causes mail delivery process to consume large amounts of CPU time. Use MTA capabilities to limit RFC …
- CVE-2026-27878MEDIUMCVSS 6.5EG 6.52026-06-19
A TraceQL query in Grafana Tempo with a large exemplars hint value can cause the Tempo instance to allocate an excessive amount of memory, resulting in an out-of-memory crash. This could allow an authenticated user to trigger a denial of s…
- CVE-2026-27879MEDIUMCVSS 6.5EG 6.52026-03-27
A resample query can be used to trigger out-of-memory crashes in Grafana.
- CVE-2026-27888MEDIUMCVSS 6.6EG 6.62026-02-26
pypdf is a free and open-source pure-python PDF library. Prior to 6.7.3, an attacker who uses this vulnerability can craft a PDF which leads to the RAM being exhausted. This requires accessing the `xfa` property of a reader or writer and t…
- CVE-2026-27980MEDIUMCVSS 7.5EG 6.92026-03-18
Next.js is a React framework for building full-stack web applications. Starting in version 10.0.0 and prior to version 16.1.7, the default Next.js image optimization disk cache (`/_next/image`) did not have a configurable upper bound, allo…
- CVE-2026-28221MEDIUMCVSS 6.5EG 6.52026-04-29
Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.8.0 to before version 4.14.4, a stack-based buffer overflow exists in print_hex_string() in wazuh-remoted. The bug is triggered wh…
- CVE-2026-28318CRITICALCVSS 7.5EG 9.0⚠ KEV2026-06-04
SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provided to secure customer environments in the SolarWinds Trust…
- CVE-2026-28342HIGHCVSS 7.5EG 7.52026-03-05
OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.10.2, the PasswordHash API endpoint allows unauthenticated users to trigger excessive memory allocation by sending concurrent password hashing r…
- CVE-2026-28351MEDIUMCVSS 5.3EG 5.32026-02-27
pypdf is a free and open-source pure-python PDF library. Prior to version 6.7.4, an attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires parsing the content stream using the RunLengthDecode …
- CVE-2026-28375MEDIUMCVSS 6.5EG 6.52026-03-27
A testdata data-source can be used to trigger out-of-memory crashes in Grafana.
- CVE-2026-28412HIGHCVSS 7.5EG 7.52026-03-02
Textream is a free macOS teleprompter app. Prior to version 1.5.1, the `DirectorServer` WebSocket server imposes no limit on concurrent connections. Combined with a broadcast timer that sends state to all connected clients every 100 ms, an…
- CVE-2026-28435HIGHCVSS 7.5EG 7.52026-03-04
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.35.0, cpp-httplib (httplib.h) does not enforce Server::set_payload_max_length() on the decompressed request body when using HandlerWithContentRead…
- CVE-2026-28575MEDIUMCVSS 5.5EG 5.52026-06-17
In PackageInstaller.Session#transfer of frameworks/base/services/core/java/com/android/server/pm/PackageInstallerSession.java, there is a possible memory exhaustion attack due to a logic error in the code. This could lead to local denial o…
- CVE-2026-28789HIGHCVSS 7.5EG 7.52026-03-05
OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.10.3, an unauthenticated denial-of-service vulnerability exists in OliveTin’s OAuth2 login flow. Concurrent requests to /oauth/login can trigg…
- CVE-2026-28872HIGHCVSS 7.5EG 7.52026-05-11
A resource exhaustion issue was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and iPadOS 26.4. A remote attacker may be able to cause a denial-of-service.
- CVE-2026-28874HIGHCVSS 7.5EG 7.52026-03-25
The issue was addressed with improved checks. This issue is fixed in iOS 26.4 and iPadOS 26.4. A remote attacker may cause an unexpected app termination.
- CVE-2026-28908HIGHCVSS 7.5EG 7.52026-05-11
A denial of service issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to modify protected parts of the file system.
- CVE-2026-2891HIGHCVSS 8.2EG 8.22026-07-01
The following Poly Voice IP devices, CCX, Trio, and Edge E, might be inoperable if they connect to a malicious SIP server and receive malformed data. HP is releasing updates to mitigate these potential vulnerabilities.
- CVE-2026-28967MEDIUMCVSS 4.9EG 4.92026-05-11
A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4. An attacker in a privileged network position may be able to cause a denial-of-service.
- CVE-2026-29049MEDIUMCVSS 4.3EG 4.32026-03-02
melange allows users to build apk packages using declarative pipelines. In version 0.40.5 and prior, melange update-cache downloads URIs from build configs via io.Copy without any size limit or HTTP client timeout (pkg/renovate/cache/cache…
- CVE-2026-29776LOWCVSS 3.1EG 3.12026-03-13
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, Integer Underflow in update_read_cache_bitmap_order Function of FreeRDP's Core Library This vulnerability is fixed in 3.24.0.
- CVE-2026-29856HIGHCVSS 7.5EG 7.52026-03-18
An issue in the VirtualHost configuration handling/parser component of aaPanel v7.57.0 allows attackers to cause a Regular Expression Denial of Service (ReDoS) via a crafted input.
- CVE-2026-30041HIGHCVSS 7.5EG 7.52026-06-26
An integer overflow in the PSD parser compnent of FastStone Image Viewer v8.3 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via supplying a crafted PSD file.
- CVE-2026-30141CRITICALCVSS 9.8EG 9.82026-06-09
An issue was discovered in bitbank2 AnimatedGIF v2.2.0. A buffer overflow in the DecodeLZW function allows remote attackers to cause a denial of service (crash) or potentially execute arbitrary code via a crafted GIF file.
- CVE-2026-30350HIGHCVSS 7.5EG 7.52026-04-27
An issue in the /store/items/search endpoint of Agent Protocol server commit e9a89f allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
- CVE-2026-30405HIGHCVSS 7.5EG 7.52026-03-16
An issue in GoBGP gobgpd v.4.2.0 allows a remote attacker to cause a denial of service via the NEXT_HOP path attribute
- CVE-2026-30653HIGHCVSS 7.5EG 7.52026-03-24
An issue in Free5GC v.4.2.0 and before allows a remote attacker to cause a denial of service via the function HandleAuthenticationFailure of the component AMF
Map vulnerabilities like CWE-400 to your infrastructure
EchelonGraph correlates every CVE — across CWE-400 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →