CWE-400
Uncontrolled Resource Consumption (DoS)
MITRENo catalog description on file. The MITRE CWE site has the canonical reference.
Recent CVEs
showing 50 of 58- CVE-2026-46374—EPSS 0%2 h ago
—
pypi - CVE-2026-50645High· 7.5EPSS 0%12 h ago
There is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache CXF, which can lead to uncontrolled resource consumption or a denial of service attack. Users are recommended to upgrad
- CVE-2026-40988High· 7.5EPSS 0%16 h ago
An application using spring-security-saml2-service-provider and the REDIRECT binding for SAML 2.0 Login or Logout may be vulnerable to a denial of service by way of an unbounded writer that inflates the compressed SAML payload into memory.
- CVE-2026-47244—EPSS 0%17 h ago
Netty HTTP/2: Advertised MAX_CONCURRENT_STREAMS are not enforced
maven - CVE-2026-48043—EPSS 0%17 h ago
netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion
maven - CVE-2026-44250—EPSS 0%17 h ago
Netty: Memory Exhaustion in RedisArrayAggregator due to Deeply Nested Arrays
maven - CVE-2026-44890—EPSS 0%17 h ago
Netty has Unbounded Direct Memory Consumption in its RedisDecoder
maven - CVE-2026-45149Medium· 6.5EPSS 0%18 h ago
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. From 5.0.0 to before 5.0.6, the max option was being applied too late. When expanding a single large numeric range like {1..10000000}, the sequen
npm - CVE-2026-11790Medium· 4.9EPSS 0%18 h ago
A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password storage plugin does not enforce an upper bound on the iteration count extracted from stored password hashes. A privileged attacker who can modify a user's password hash ca
- CVE-2026-44496High· 7.5EPSS 0%19 h ago
Axios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and before 1.16.0 on the 1.x line build a regular expression from the configured XSRF cookie name without escaping regex metachar
npm - CVE-2026-28318—· 7.5KEVEPSS 6%20 h ago
SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability
- CVE-2023-44487High· 7.5KEVEXPLOITEPSS 94%20 h ago
HTTP/2 Rapid Reset Attack Vulnerability
- CVE-2021-44228Critical· 10.0KEVEXPLOITEPSS 94%20 h ago
Apache Log4j2 Remote Code Execution Vulnerability
- CVE-2020-3566High· 8.6KEVEPSS 2%20 h ago
Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability
- CVE-2020-3569High· 8.6KEVEPSS 5%20 h ago
Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability
- CVE-2025-55658Medium· 6.5EPSS 0%20 h ago
GPAC MP4Box v2.4 was discovered to contain a floating point exception in the gf_opus_parse_packet_header function (media_tools/av_parsers.c). bThis vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.
- CVE-2025-52293High· 7.5EPSS 0%20 h ago
A segmentation violaton in the gf_hevc_read_sps_bs_internal function (media_tools/av_parsers.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying crafted HEVC SPS data.
- CVE-2026-50011High· 7.520 h ago
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, RedisArrayAggregator pre-allocates ArrayList with initial capacity equal to the RESP array element c
- CVE-2026-44892High· 7.5EPSS 0%21 h ago
Netty has a Vulnerable Default Configuration Which Leads to Denial of Service via Unbounded HTTP/3 Header Size
maven - CVE-2026-45169—EPSS 0%21 h ago
Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a validation vulnerability. Under specific circumstances and configuration scenarios, processing unexpected input could pot
- CVE-2026-45802—EPSS 0%1 d ago
FPDI is a collection of PHP classes that facilitate reading pages from existing PDF documents and using them as templates in FPDF. Prior to version 2.6.7, an attacker can upload a small, malicious PDF file that will cause the server-side sc
- CVE-2026-10143High· 7.5EPSS 0%1 d ago
kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in SCRAM authentication handling that allows a malicious or machine-in-the-middle broker to freeze the client event loop by supplying an excessively large iteration coun
- CVE-2026-46522High· 7.5EPSS 1%1 d ago
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2.23 and 6.9.13-48, due to a missing check in the MIFF decoder, a crafted file could cause an infinite loop resulting in CP
- CVE-2026-45664Medium· 5.3EPSS 0%1 d ago
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, because of a missing check in the MNG coder it would be possible to read more images than the list limi
- CVE-2026-45031Medium· 5.3EPSS 0%1 d ago
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, due to a missing check in the PSD decoder it would be possible to bypass the list-length resource polic
- CVE-2026-45783High· 7.5EPSS 0%1 d ago
libp2p is a JavaScript Implementation of libp2p networking stack. Prior to version 16.2.6, an unauthenticated remote peer can exhaust the disk storage of any @libp2p/kad-dht node running in server mode by sending an unbounded stream of PUT_
npm - CVE-2026-46679High· 7.5EPSS 0%1 d ago
libp2p is a JavaScript Implementation of libp2p networking stack. Prior to version 15.0.23, three cooperating omissions in @libp2p/gossipsub allow an unauthenticated single peer to exhaust the Node.js heap of any gossipsub node with default
npm - CVE-2026-5497High· 7.5EPSS 0%1 d ago
vLLM versions 0.8.0 and later are vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded frame count processing in the `VideoMediaIO.load_base64()` method. When processing `video/jpeg` data URLs, the method spl
- CVE-2026-46689—EPSS 0%1 d ago
Kanidm is an identity management platform. Prior to version 1.9.3, a single unauthenticated GET to any /scim/v1/... endpoint with a ?filter= query string of a few thousand nested parentheses (≈ 4–12 KB) drives the recursive-descent PEG pars
- CVE-2026-47734—EPSS 0%1 d ago
Dulwich has unbounded memory allocation in receive-pack from crafted thin packs
pypi - CVE-2026-30141Critical· 9.8EPSS 0%2 d ago
An issue was discovered in bitbank2 AnimatedGIF v2.2.0. A buffer overflow in the DecodeLZW function allows remote attackers to cause a denial of service (crash) or potentially execute arbitrary code via a crafted GIF file.
- CVE-2026-36724Medium· 6.5EPSS 0%2 d ago
An uncaught exception in the /application/job/update/{id} endpoint of FastapiAdmin v2.2.0 allows authenticated attackers with the module_task:job:update permission to cause a Denial of Service (DoS) via manipulating the func field of schedu
- CVE-2026-41711Medium· 5.9EPSS 0%2 d ago
Applications using Spring Data Commons may be vulnerable to a Denial of Service (DoS) attack leading to a StackOverflowException when parsing Sort parameters. Affected versions: Spring Data Commons 4.0.0 through 4.0.5; 3.5.0 through 3.5.11
- CVE-2026-41695High· 7.5EPSS 0%2 d ago
Spring Data Commons applications may be vulnerable to denial of service through resource exhaustion when attacker-controlled property path strings are passed to MappingContext property path resolution. Affected versions: Spring Data Common
- CVE-2026-41721Medium· 5.9EPSS 0%2 d ago
Spring Data Commons contains a vulnerability that can lead to a Denial of Service (DoS) condition if Spring Data Web Support is enabled in conjunction with a Controller method using @ProjectedPayload, when an attacker sends a specially craf
- CVE-2026-47904Medium· 6.2EPSS 0%2 d ago
CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consumption vulnerability. An attacker could exploit this vulnerability to exhaust system resources, resulting in an applicat
- CVE-2026-47905Medium· 6.2EPSS 0%2 d ago
CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consumption vulnerability. An attacker could exploit this vulnerability to exhaust system resources, resulting in an applicat
- CVE-2026-34713High· 7.5EPSS 0%2 d ago
CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consumption vulnerability. An attacker could exploit this vulnerability to exhaust system resources, resulting in an applicat
- CVE-2026-47902Medium· 6.2EPSS 0%2 d ago
CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consumption vulnerability. An attacker could exploit this vulnerability to exhaust system resources, resulting in an applicat
- CVE-2026-38361High· 7.5EPSS 1%2 d ago
Multiple unauthenticated denial-of-service (DoS) issues in fohrloop dash-uploader v0.1.0 through v0.7.0a2. The chunked-upload handler (dash_uploader/httprequesthandler.py, dash_uploader/upload.py) trusts unsanitized, attacker-controlled upl
- CVE-2026-49160High· 7.5EPSS 1%2 d ago
Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network.
- CVE-2026-49842High· 7.5EPSS 0%2 d ago
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, mod_verto's WebSocket frame loop
- CVE-2026-34678Medium· 6.2EPSS 0%3 d ago
CAI Content Credentials versions c2pa-web@0.7.0, c2pa-v0.78.2 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to e
- CVE-2026-34677Medium· 6.2EPSS 0%3 d ago
CAI Content Credentials versions c2pa-web@0.7.0, c2pa-v0.78.2 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to e
- CVE-2026-34673Medium· 6.2EPSS 0%3 d ago
CAI Content Credentials versions c2pa-web@0.7.0, c2pa-v0.78.2 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to e
- CVE-2026-34665High· 7.5EPSS 0%3 d ago
CAI Content Credentials versions c2pa-web@0.7.0, c2pa-v0.78.2 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to e
- CVE-2026-41840Medium· 5.9EPSS 0%3 d ago
Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
- CVE-2026-41842High· 7.5EPSS 0%3 d ago
Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.4
- CVE-2026-45591High· 7.5EPSS 2%3 d ago
Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network.
- CVE-2026-49762—EPSS 0%3 d ago
Uncontrolled Resource Consumption vulnerability in the Elixir standard library's Version module allows an attacker who controls a version string to cause a denial of service through CPU and memory exhaustion. The version parser converts nu
CWE catalog data sourced from MITRE. CVE associations come from NVD weakness mappings; some CVEs carry multiple CWEs.