VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (4,104)

page 191 of 206
  • CVE-2026-9602MedJul 17, 2026
    risk 0.00cvss 6.5epss 0.00

    Mattermost Desktop App versions <=6.2 6.0.2 5.6.13.0 fail to validate payloads sent from the Mattermost Web App to the Desktop App which allows a malicious server owner to crash the Mattermost Desktop App via changing the payload of a method to a malformed one. Mattermost…

  • CVE-2026-33754MedJul 17, 2026
    risk 0.00cvss 6.5epss 0.00

    Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 3.9.0 and above, prior to 4.14.5, a remote attacker can trigger memory exhaustion in the cluster protocol parser by sending a crafted message header with an arbitrarily…

  • CVE-2026-55440MedJul 16, 2026
    risk 0.00cvss 6.5epss 0.01

    Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.7, the COMMAND_RESULTS handler in ufo/server/ws/handler.py called get_or_create_session in ufo/server/services/session_manager.py without owner_client_id, allowing an…

  • CVE-2026-52890HigJul 15, 2026
    risk 0.00cvss 7.1epss 0.00

    Wekan is open source kanban built with Meteor. Prior to 9.31, Wekan allows a logged-in board member to insert an attachment document through the /attachments/insert DDP method with attacker-controlled versions.original.path and versions.original.storage fields. The…

  • CVE-2026-36590HigJul 15, 2026
    risk 0.00cvss 7.5epss 0.01

    An issue in EMQ NanoMQ v.0.24.9 allows a remote attacker to cause a denial of service via the nni_qos_db_set function in broker_tcp.c component

  • CVE-2026-55399MedJul 15, 2026
    risk 0.00cvss 4.3epss 0.00

    CVE-2026-55399 is a resource exhaustion vulnerability in the Secure Access publisher prior to 14.55. Attackers with valid credentials to the Secure Access tunnel can create a non-persistent DoS against the publisher.

  • CVE-2026-55398LowJul 15, 2026
    risk 0.00cvss 3.7epss 0.00

    CVE-2026-55398 is a memory management vulnerability in Secure Access clients and servers prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against the server.

  • CVE-2026-33445MedJul 15, 2026
    risk 0.00cvss 5.9epss 0.00

    CVE-2026-33445 is a memory management vulnerability in Secure Access servers prior to 14.55. Attackers with an intimate knowledge of and total control over the tunnel protocol can create a persistent DoS against the server.

  • CVE-2026-33444LowJul 15, 2026
    risk 0.00cvss 3.7epss 0.00

    CVE-2026-33444 is a memory management vulnerability in Secure Access servers prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against the server.

  • CVE-2026-33443MedJul 15, 2026
    risk 0.00cvss 5.9epss 0.00

    CVE-2026-33443 is a memory management error in Secure Access servers prior to 14.55. Attackers with an intimate knowledge of and total control over the tunnel protocol can create a persistent DoS against the server.

  • CVE-2026-47479HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.00

    NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service.

  • CVE-2026-58627HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.01

    Uncontrolled resource consumption in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

  • CVE-2026-50653HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.01

    Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.

  • CVE-2026-49799MedJul 14, 2026
    risk 0.00cvss 6.5epss 0.01

    Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network.

  • CVE-2026-58486HigJul 13, 2026
    risk 0.00cvss —epss 0.00

    HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to version 1.11.0, HedgeDoc was vulnerable to a YAML alias bomb due to unsafe processing of the note frontmatter. HedgeDoc parsed frontmatter with js-yaml.load (js-yaml v3) via…

  • CVE-2026-51539HigJul 13, 2026
    risk 0.00cvss 7.5epss 0.00

    A Denial of Service (DoS) vulnerability exists in the receive loop of libmodbus 3.1.12 when running on Windows. The issue stems from improper timeout management during network read operations.

  • CVE-2026-55782LowJul 10, 2026
    risk 0.00cvss —epss 0.00

    NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's WebAssembly archive handler in NanaZip.Codecs.Archive.WebAssembly.cpp allocates buffers from attacker-controlled 32-bit section and custom-name length fields without…

  • CVE-2026-55781LowJul 10, 2026
    risk 0.00cvss —epss 0.00

    NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's UFS and FFS image handler in NanaZip.Codecs.Archive.Ufs.cpp validates the superblock block size only against the MINBSIZE lower bound and does not validate the fs_fsize…

  • CVE-2026-55780LowJul 10, 2026
    risk 0.00cvss —epss 0.00

    NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's .NET single-file bundle handler in NanaZip.Codecs.Archive.DotNetSingleFile.cpp sizes its extraction buffer from the bundle entry Size field, which is only checked for sign…

  • CVE-2026-40007HigJul 10, 2026
    risk 0.00cvss 7.5epss 0.00

    Uncontrolled Recursion, Uncontrolled Resource Consumption vulnerability in Apache IoTDB. When pipe_air_gap_receiver_enabled=true, the IoTDB AirGap receiver's readLength method calls itself recursively each time it recognises the E-language prefix in socket data, with no depth…