VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (3,811)

page 177 of 191
  • CVE-2026-55782LowJul 10, 2026
    risk 0.00cvss epss 0.00

    NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's WebAssembly archive handler in NanaZip.Codecs.Archive.WebAssembly.cpp allocates buffers from attacker-controlled 32-bit section and custom-name length fields without…

  • CVE-2026-55781LowJul 10, 2026
    risk 0.00cvss epss 0.00

    NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's UFS and FFS image handler in NanaZip.Codecs.Archive.Ufs.cpp validates the superblock block size only against the MINBSIZE lower bound and does not validate the fs_fsize…

  • CVE-2026-55780LowJul 10, 2026
    risk 0.00cvss epss 0.00

    NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's .NET single-file bundle handler in NanaZip.Codecs.Archive.DotNetSingleFile.cpp sizes its extraction buffer from the bundle entry Size field, which is only checked for sign…

  • CVE-2026-40007HigJul 10, 2026
    risk 0.00cvss 7.5epss 0.00

    Uncontrolled Recursion, Uncontrolled Resource Consumption vulnerability in Apache IoTDB. When pipe_air_gap_receiver_enabled=true, the IoTDB AirGap receiver's readLength method calls itself recursively each time it recognises the E-language prefix in socket data, with no depth…

  • CVE-2026-51600HigJul 9, 2026
    risk 0.00cvss 7.5epss 0.00

    Tenda CP3 V3.0 firmware V31.1.9.91 does not validate the Content-Length header field in RTSP requests (including DESCRIBE, SETUP, and PLAY methods). When a request carrying a Content-Length header is received without a corresponding message body, the RTSP parser enters a…

  • CVE-2026-51535HigJul 8, 2026
    risk 0.00cvss 7.5epss 0.00

    In OpENer 2.3.0 (commit 76b95cf), a resource exhaustion (Denial of Service) vulnerability exists in its network processing loop.

  • CVE-2026-40140HigJul 6, 2026
    risk 0.00cvss 7.5epss 0.01

    BeyondTrust Remote Support and Privileged Remote Access contain a high-severity pre-authentication vulnerability in the network communication subsystem. Insufficient validation of client-supplied input may allow an unauthenticated remote attacker to trigger a denial-of-service…

  • CVE-2026-24012HigJul 6, 2026
    risk 0.00cvss 7.5epss 0.01

    Uncontrolled Resource Consumption vulnerability in Apache IoTDB.  Some interface fails to impose reasonable limits on the time span and aggregation interval of the query. An attacker can construct a request with extreme parameters (e.g., a very large time range combined with…

  • CVE-2026-26307HigJul 3, 2026
    risk 0.00cvss 7.5epss 0.00

    Gitea versions before 1.25.5 do not enforce a timeout on git grep searches, allowing expensive searches to consume server resources.

  • CVE-2026-52192HigJul 2, 2026
    risk 0.00cvss 7.5epss 0.00

    An issue in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_445C5C component

  • CVE-2026-54260MedJul 1, 2026
    risk 0.00cvss 4.3epss 0.00

    Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, an authenticated admin user can trigger expensive rendition processing with purposefully crafted filter specs resulting in potentially service degradation. The…

  • CVE-2026-49090MedJul 1, 2026
    risk 0.00cvss 6.5epss 0.00

    Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted bulk request that causes sustained high CPU consumption, which can render the affected node…

  • CVE-2026-2891HigJul 1, 2026
    risk 0.00cvss epss 0.00

    The following Poly Voice IP devices, CCX, Trio, and Edge E, might be inoperable if they connect to a malicious SIP server and receive malformed data. HP is releasing updates to mitigate these potential vulnerabilities.

  • CVE-2026-52197HigJun 30, 2026
    risk 0.00cvss 7.5epss 0.00

    An issue in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_44af70 component

  • CVE-2026-9002MedJun 30, 2026
    risk 0.00cvss 6.5epss 0.00

    IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 could allow an adjacent attacker to cause a denial of service due to improper validation in the XDF decoder. The application processes deeply nested Protocol Buffers messages and attacker-controlled length prefixes without…

  • CVE-2026-57081HigJun 30, 2026
    risk 0.00cvss 7.5epss 0.00

    Net::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustion via deeply nested bencoded input. bdecode recurses once per nested list or dictionary level with no depth cap, and each recursive call receives the remaining buffer by value while the list and…

  • CVE-2026-57080HigJun 30, 2026
    risk 0.00cvss 7.5epss 0.00

    Net::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustion via an uncapped peer-wire message-length prefix. The peer-wire framing in _process_messages trusts the 4-byte length prefix sent by a connected peer with no upper bound, while receive_data appends…

  • CVE-2026-36478HigJun 26, 2026
    risk 0.00cvss 7.5epss 0.00

    An issue in Technitium DNS Server v.14.3 and before allows a remote attacker to cause a denial of service via the DnsServerApp.exe, DnsServerApp.dll, TechnitiumLibrary.Net/Dns/DnsClient.cs components

  • CVE-2026-30041HigJun 26, 2026
    risk 0.00cvss 7.5epss 0.01

    An integer overflow in the PSD parser compnent of FastStone Image Viewer v8.3 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via supplying a crafted PSD file.

  • CVE-2026-38640HigJun 25, 2026
    risk 0.00cvss 7.5epss 0.00

    A reachable unwrap in the __assert_fail function (/assert/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted string.