CWE-400
Uncontrolled Resource Consumption
Description
The product does not properly control the allocation and maintenance of a limited resource.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-147 · CAPEC-227 · CAPEC-492
CVEs mapped to this weakness (4,133)
page 184 of 207| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-35358 | Med | 0.22 | 4.4 | 0.00 | Apr 22, 2026 | The cp utility in uutils coreutils, when performing recursive copies (-R), incorrectly treats character and block device nodes as stream sources rather than preserving them. Because the implementation reads bytes into regular files at the destination instead of using mknod,… | ||
| CVE-2024-37535 | Med | 0.22 | 4.4 | 0.00 | Jun 9, 2024 | GNOME VTE before 0.76.3 allows an attacker to cause a denial of service (memory consumption) via a window resize escape sequence, a related issue to CVE-2000-0476. | ||
| CVE-2023-28938 | Low | 0.22 | 3.4 | 0.00 | Aug 11, 2023 | Uncontrolled resource consumption in some Intel(R) SSD Tools software before version mdadm-4.2-rc2 may allow a priviledged user to potentially enable denial of service via local access. | ||
| CVE-2023-37900 | Low | 0.22 | 3.4 | 0.01 | Jul 27, 2023 | Crossplane is a framework for building cloud native control planes without needing to write code. In versions prior to 1.11.5, 1.12.3, and 1.13.0, a high-privileged user could create a Package referencing an arbitrarily large image containing that Crossplane would then parse,… | ||
| CVE-2023-26437 | Low | 0.22 | 3.4 | 0.01 | Apr 4, 2023 | Denial of service vulnerability in PowerDNS Recursor allows authoritative servers to be marked unavailable.This issue affects Recursor: through 4.6.5, through 4.7.4 , through 4.8.3. | ||
| CVE-2020-1702 | Low | 0.22 | 3.3 | 0.01 | May 27, 2021 | A malicious container image can consume an unbounded amount of memory when being pulled to a container runtime host, such as Red Hat Enterprise Linux using podman, or OpenShift Container Platform. An attacker can use this flaw to trick a user, with privileges to pull container… | ||
| CVE-2021-23351 | Med | 0.22 | 4.4 | 0.02 | Mar 8, 2021 | The package github.com/pires/go-proxyproto before 0.5.0 are vulnerable to Denial of Service (DoS) via the parseVersion1() function. The reader in this package is a default bufio.Reader wrapping a net.Conn. It will read from the connection until it finds a newline. Since no… | ||
| CVE-2026-101098 | Med | 0.21 | 4.3 | 0.01 | Sep 28, 2026 | A security vulnerability has been detected in ag-ui-protocol ag-ui up to 2026-09-23. Affected by this issue is the function readAllBytes of the file JdkAgentHttpHandler.java of the component HTTP Handler. Such manipulation leads to resource consumption. The attack can be… | ||
| CVE-2026-92879 | Med | 0.21 | 4.3 | 0.01 | Sep 17, 2026 | A security flaw has been discovered in vgmstream up to r2117. This issue affects the function parse_mus of the file src/meta/mus_acm.c. The manipulation results in resource consumption. The attack may be launched remotely. The patch is identified as… | ||
| CVE-2026-92363 | Med | 0.21 | 4.3 | 0.01 | Sep 16, 2026 | A flaw has been found in ag-ui-protocol ag-ui 1.0. Affected is an unknown function of the file src/stream/sse_parser.cpp of the component JSON Parser. Executing a manipulation can lead to resource consumption. The attack may be performed from remote. This patch is called… | ||
| CVE-2026-92361 | Med | 0.21 | 4.3 | 0.01 | Sep 16, 2026 | A security vulnerability has been detected in ag-ui-protocol ag-ui 1.0. This affects an unknown function of the file sdks/community/go/pkg/client/sse/client.go of the component SSE Client. Such manipulation leads to resource consumption. The attack can be executed remotely. The… | ||
| CVE-2026-53954 | Med | 0.21 | 4.3 | 0.01 | Sep 15, 2026 | Bugsink is a self-hosted error tracking tool. Prior to version 2.2.2, Bugsink stores every set of custom tags supplied with an incoming event, allowing a caller with a valid project DSN to submit an unusually large tag set and force excessive tag-row writes. Because Bugsink uses… | ||
| CVE-2026-90878 | Med | 0.21 | 4.3 | 0.01 | Sep 15, 2026 | A vulnerability was determined in vllm-project vLLM up to 0.27.1. This affects an unknown part of the file /v1/chat/completions of the component Jinja Template Rendering. This manipulation of the argument chat_template causes resource consumption. The attack can be initiated… | ||
| CVE-2026-86515 | Med | 0.21 | 4.3 | 0.01 | Sep 8, 2026 | A security vulnerability has been detected in vgmstream up to r2117. Impacted is the function add_entry of the file src/meta/txtp_parser.c of the component txtp. Such manipulation of the argument range_start/range_end leads to resource consumption. The attack may be performed… | ||
| CVE-2026-71486 | Med | 0.21 | 4.3 | 0.00 | Aug 17, 2026 | vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the /v1/completions/derender and /v1/chat/completions/derender endpoints accept caller-supplied GenerateResponse objects whose generate_responses, choices, token_ids, prompt_logprobs,… | ||
| CVE-2026-72912 | Med | 0.21 | 4.3 | 0.00 | Aug 10, 2026 | CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.3.0, CyberChef's pretty-recipe parser in src/core/Utils.mjs can exhaust client-side CPU when a malformed #recipe= URL fragment containing a large number of unmatched quote characters… | ||
| CVE-2026-47022 | Low | 0.21 | 3.3 | 0.00 | Jul 21, 2026 | Vulnerability in the GoldenGate Stream Analytics product of Oracle GoldenGate (component: Security). The supported version that is affected is 26.1.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where GoldenGate Stream… | ||
| CVE-2026-10675 | Med | 0.21 | 4.3 | 0.00 | Jul 21, 2026 | In Zephyr's Bluetooth Mesh PB-ADV provisioning bearer (subsys/bluetooth/mesh/pb_adv.c), prov_msg_recv() rescheduled the provisioning protocol watchdog timer unconditionally at the top of the function, before the FCS check and before the ADV_LINK_INVALID check. Once a… | ||
| CVE-2026-14684 | Low | 0.21 | 3.3 | 0.00 | Jul 5, 2026 | A flaw has been found in HdrHistogram up to 2.2.2. This affects the function org.HdrHistogram.AbstractHistogram.decodeFromByteBuffer of the file src/main/java/org/HdrHistogram/AbstractHistogram.java. This manipulation of the argument numberOfSignificantValueDigits causes… | ||
| CVE-2026-14683 | Low | 0.21 | 3.3 | 0.00 | Jul 4, 2026 | A vulnerability was detected in HdrHistogram up to 2.2.2. Affected by this issue is the function org.HdrHistogram.AbstractHistogram.decodeFromCompressedByteBuffer of the file src/main/java/org/HdrHistogram/AbstractHistogram.java. The manipulation of the argument… |
- risk 0.22cvss 4.4epss 0.00
The cp utility in uutils coreutils, when performing recursive copies (-R), incorrectly treats character and block device nodes as stream sources rather than preserving them. Because the implementation reads bytes into regular files at the destination instead of using mknod,…
- risk 0.22cvss 4.4epss 0.00
GNOME VTE before 0.76.3 allows an attacker to cause a denial of service (memory consumption) via a window resize escape sequence, a related issue to CVE-2000-0476.
- risk 0.22cvss 3.4epss 0.00
Uncontrolled resource consumption in some Intel(R) SSD Tools software before version mdadm-4.2-rc2 may allow a priviledged user to potentially enable denial of service via local access.
- risk 0.22cvss 3.4epss 0.01
Crossplane is a framework for building cloud native control planes without needing to write code. In versions prior to 1.11.5, 1.12.3, and 1.13.0, a high-privileged user could create a Package referencing an arbitrarily large image containing that Crossplane would then parse,…
- risk 0.22cvss 3.4epss 0.01
Denial of service vulnerability in PowerDNS Recursor allows authoritative servers to be marked unavailable.This issue affects Recursor: through 4.6.5, through 4.7.4 , through 4.8.3.
- risk 0.22cvss 3.3epss 0.01
A malicious container image can consume an unbounded amount of memory when being pulled to a container runtime host, such as Red Hat Enterprise Linux using podman, or OpenShift Container Platform. An attacker can use this flaw to trick a user, with privileges to pull container…
- risk 0.22cvss 4.4epss 0.02
The package github.com/pires/go-proxyproto before 0.5.0 are vulnerable to Denial of Service (DoS) via the parseVersion1() function. The reader in this package is a default bufio.Reader wrapping a net.Conn. It will read from the connection until it finds a newline. Since no…
- risk 0.21cvss 4.3epss 0.01
A security vulnerability has been detected in ag-ui-protocol ag-ui up to 2026-09-23. Affected by this issue is the function readAllBytes of the file JdkAgentHttpHandler.java of the component HTTP Handler. Such manipulation leads to resource consumption. The attack can be…
- risk 0.21cvss 4.3epss 0.01
A security flaw has been discovered in vgmstream up to r2117. This issue affects the function parse_mus of the file src/meta/mus_acm.c. The manipulation results in resource consumption. The attack may be launched remotely. The patch is identified as…
- risk 0.21cvss 4.3epss 0.01
A flaw has been found in ag-ui-protocol ag-ui 1.0. Affected is an unknown function of the file src/stream/sse_parser.cpp of the component JSON Parser. Executing a manipulation can lead to resource consumption. The attack may be performed from remote. This patch is called…
- risk 0.21cvss 4.3epss 0.01
A security vulnerability has been detected in ag-ui-protocol ag-ui 1.0. This affects an unknown function of the file sdks/community/go/pkg/client/sse/client.go of the component SSE Client. Such manipulation leads to resource consumption. The attack can be executed remotely. The…
- risk 0.21cvss 4.3epss 0.01
Bugsink is a self-hosted error tracking tool. Prior to version 2.2.2, Bugsink stores every set of custom tags supplied with an incoming event, allowing a caller with a valid project DSN to submit an unusually large tag set and force excessive tag-row writes. Because Bugsink uses…
- risk 0.21cvss 4.3epss 0.01
A vulnerability was determined in vllm-project vLLM up to 0.27.1. This affects an unknown part of the file /v1/chat/completions of the component Jinja Template Rendering. This manipulation of the argument chat_template causes resource consumption. The attack can be initiated…
- risk 0.21cvss 4.3epss 0.01
A security vulnerability has been detected in vgmstream up to r2117. Impacted is the function add_entry of the file src/meta/txtp_parser.c of the component txtp. Such manipulation of the argument range_start/range_end leads to resource consumption. The attack may be performed…
- risk 0.21cvss 4.3epss 0.00
vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the /v1/completions/derender and /v1/chat/completions/derender endpoints accept caller-supplied GenerateResponse objects whose generate_responses, choices, token_ids, prompt_logprobs,…
- risk 0.21cvss 4.3epss 0.00
CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.3.0, CyberChef's pretty-recipe parser in src/core/Utils.mjs can exhaust client-side CPU when a malformed #recipe= URL fragment containing a large number of unmatched quote characters…
- risk 0.21cvss 3.3epss 0.00
Vulnerability in the GoldenGate Stream Analytics product of Oracle GoldenGate (component: Security). The supported version that is affected is 26.1.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where GoldenGate Stream…
- risk 0.21cvss 4.3epss 0.00
In Zephyr's Bluetooth Mesh PB-ADV provisioning bearer (subsys/bluetooth/mesh/pb_adv.c), prov_msg_recv() rescheduled the provisioning protocol watchdog timer unconditionally at the top of the function, before the FCS check and before the ADV_LINK_INVALID check. Once a…
- risk 0.21cvss 3.3epss 0.00
A flaw has been found in HdrHistogram up to 2.2.2. This affects the function org.HdrHistogram.AbstractHistogram.decodeFromByteBuffer of the file src/main/java/org/HdrHistogram/AbstractHistogram.java. This manipulation of the argument numberOfSignificantValueDigits causes…
- risk 0.21cvss 3.3epss 0.00
A vulnerability was detected in HdrHistogram up to 2.2.2. Affected by this issue is the function org.HdrHistogram.AbstractHistogram.decodeFromCompressedByteBuffer of the file src/main/java/org/HdrHistogram/AbstractHistogram.java. The manipulation of the argument…