VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (4,104)

page 18 of 206
  • CVE-2026-51788HigSep 1, 2026
    risk 0.49cvss 7.5epss 0.01

    An issue in cleverange_auth v.0.1.10 allows a remote attacker to cause a denial of service via the account_verification function and the accounts/models.py component

  • CVE-2026-38638HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.00

    An issue in the with_argv function (/unistd/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2026-38636HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.00

    An issue in the seekdir() function (/dirent/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2026-42391HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.00

    An unauthenticated attacker can send an IMAP ID command with a very large number of parameters before logging in, which causes memory and CPU usage to grow disproportionately. The login process can be terminated by the out-of-memory handling, which also terminates all other…

  • CVE-2026-33605HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.00

    An unauthenticated attacker can crash the ManageSieve login process by sending a small malformed command before authenticating. If running in high-security mode (default for community releases), only the attacker's own connection is terminated. If running in high-performance…

  • CVE-2026-27852HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.00

    An attacker that can send mail to a user can craft a message whose headers contain a very large number of email addresses or MIME parameters, which causes excessive memory usage when the message is later parsed. The message is still delivered, but reading it over IMAP can…

  • CVE-2026-59282HigAug 27, 2026
    risk 0.49cvss 7.5epss 0.00

    Spring Framework applications that use Spring's data binding infrastructure to apply user-supplied property paths onto a target object may be vulnerable to a Denial of Service (DoS) attack. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 -…

  • CVE-2026-47886HigAug 27, 2026
    risk 0.49cvss 7.5epss 0.00

    Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack when the power operator (^) is used with a BigDecimal or BigInteger operand and a large exponent value. Spring Framework 7.0.0 - 7.0.8…

  • CVE-2025-61480HigAug 26, 2026
    risk 0.49cvss 7.5epss 0.00

    An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via spoofed TCP FIN packets without validating the sequence or acknowledgment numbers.

  • CVE-2025-61478HigAug 26, 2026
    risk 0.49cvss 7.5epss 0.00

    An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via Spoofed SYN packets.

  • CVE-2026-19401HigAug 26, 2026
    risk 0.49cvss 7.5epss 0.00

    Any remote client can crash a (debugging/non-release build type) NSD serve child by sending it a special crafted message with a specially tuned number of DNS Cookie options (17 when UDP payload size is 512). By continuously crashing the serve childs, the remote client can…

  • CVE-2026-71360HigAug 25, 2026
    risk 0.49cvss 7.5epss 0.01

    CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition.…

  • CVE-2026-79658HigAug 25, 2026
    risk 0.49cvss 7.5epss 0.00

    Ech0 before 5.0.1 does not impose any size or shape limit on the Accept-Language header processed by its i18n middleware, which runs on every HTTP request. The header is passed unfiltered to go-i18n's NewLocalizer, which internally calls golang.org/x/text/language.ParseAcceptLang…

  • CVE-2026-75371HigAug 24, 2026
    risk 0.49cvss 7.5epss 0.00

    An integer handling flaw in the cobs_decode function of SpaceDot AcubeSAT OBC software commit eaf90ec allows physically-proximate attackers with UART access to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2026-4671HigAug 23, 2026
    risk 0.49cvss 7.5epss 0.00

    justhtml before 1.18.0 contains multiple low-severity denial-of-service issues in CSS selector handling and linkification. Applications that evaluate attacker-controlled selector strings (via query(), matches(), or selector-based transforms), run selector matching over very…

  • CVE-2026-19446HigAug 20, 2026
    risk 0.49cvss 7.5epss 0.01

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 allows a remote unauthenticated attacker can send a crafted UDP packet to a reachable RPC service, resulting in complete system unavailability and requiring an LPAR restart.

  • CVE-2026-17121HigAug 20, 2026
    risk 0.49cvss 7.5epss 0.00

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to uncontrolled recursion.

  • CVE-2026-19507HigAug 19, 2026
    risk 0.49cvss 7.5epss 0.00

    Uncontrolled resource consumption in `check.jst` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote unauthenticated attacker to cause denial of service via excessively large password values.

  • CVE-2026-16837HigAug 19, 2026
    risk 0.49cvss 7.5epss 0.00

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to improper handling of a missing SSL client certificate.

  • CVE-2026-16836HigAug 19, 2026
    risk 0.49cvss 7.5epss 0.00

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to uncontrolled resource consumption.