VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (4,104)

page 192 of 206
  • CVE-2026-51600HigJul 9, 2026
    risk 0.00cvss 7.5epss 0.01

    Tenda CP3 V3.0 firmware V31.1.9.91 does not validate the Content-Length header field in RTSP requests (including DESCRIBE, SETUP, and PLAY methods). When a request carrying a Content-Length header is received without a corresponding message body, the RTSP parser enters a…

  • CVE-2026-51535HigJul 8, 2026
    risk 0.00cvss 7.5epss 0.00

    In OpENer 2.3.0 (commit 76b95cf), a resource exhaustion (Denial of Service) vulnerability exists in its network processing loop.

  • CVE-2026-40140HigJul 6, 2026
    risk 0.00cvss 7.5epss 0.01

    BeyondTrust Remote Support and Privileged Remote Access contain a high-severity pre-authentication vulnerability in the network communication subsystem. Insufficient validation of client-supplied input may allow an unauthenticated remote attacker to trigger a denial-of-service…

  • CVE-2026-24012HigJul 6, 2026
    risk 0.00cvss 7.5epss 0.01

    Uncontrolled Resource Consumption vulnerability in Apache IoTDB.  Some interface fails to impose reasonable limits on the time span and aggregation interval of the query. An attacker can construct a request with extreme parameters (e.g., a very large time range combined with…

  • CVE-2026-52192HigJul 2, 2026
    risk 0.00cvss 7.5epss 0.01

    An issue in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_445C5C component

  • CVE-2026-49090MedJul 1, 2026
    risk 0.00cvss 6.5epss 0.00

    Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted bulk request that causes sustained high CPU consumption, which can render the affected node…

  • CVE-2026-2891HigJul 1, 2026
    risk 0.00cvss —epss 0.00

    The following Poly Voice IP devices, CCX, Trio, and Edge E, might be inoperable if they connect to a malicious SIP server and receive malformed data. HP is releasing updates to mitigate these potential vulnerabilities.

  • CVE-2026-52197HigJun 30, 2026
    risk 0.00cvss 7.5epss 0.01

    An issue in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_44af70 component

  • CVE-2026-9002MedJun 30, 2026
    risk 0.00cvss 6.5epss 0.00

    IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 could allow an adjacent attacker to cause a denial of service due to improper validation in the XDF decoder. The application processes deeply nested Protocol Buffers messages and attacker-controlled length prefixes without…

  • CVE-2026-57081HigJun 30, 2026
    risk 0.00cvss 7.5epss 0.00

    Net::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustion via deeply nested bencoded input. bdecode recurses once per nested list or dictionary level with no depth cap, and each recursive call receives the remaining buffer by value while the list and…

  • CVE-2026-57080HigJun 30, 2026
    risk 0.00cvss 7.5epss 0.00

    Net::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustion via an uncapped peer-wire message-length prefix. The peer-wire framing in _process_messages trusts the 4-byte length prefix sent by a connected peer with no upper bound, while receive_data appends…

  • CVE-2026-36478HigJun 26, 2026
    risk 0.00cvss 7.5epss 0.01

    An issue in Technitium DNS Server v.14.3 and before allows a remote attacker to cause a denial of service via the DnsServerApp.exe, DnsServerApp.dll, TechnitiumLibrary.Net/Dns/DnsClient.cs components

  • CVE-2026-30041HigJun 26, 2026
    risk 0.00cvss 7.5epss 0.01

    An integer overflow in the PSD parser compnent of FastStone Image Viewer v8.3 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via supplying a crafted PSD file.

  • CVE-2026-38640HigJun 25, 2026
    risk 0.00cvss 7.5epss 0.01

    A reachable unwrap in the __assert_fail function (/assert/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted string.

  • CVE-2026-38637HigJun 25, 2026
    risk 0.00cvss 7.5epss 0.01

    An issue in the pthread_rwlockattr_setpshared() function of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2025-61025HigJun 23, 2026
    risk 0.00cvss 7.5epss 0.01

    An issue in the sslr_qst_get component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

  • CVE-2026-9375Jun 19, 2026
    risk 0.00cvss —epss 0.00

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2025-32437HigJun 18, 2026
    risk 0.00cvss —epss 0.00

    AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.63, `MediaDurationBlock` will download and store the video in a temporary directory without deleting before all noded are done.…

  • CVE-2025-32424HigJun 18, 2026
    risk 0.00cvss —epss 0.00

    AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.63, ScreenshotWebPageBlock will store the captured screenshots in a temporary directory. `StepThroughItemsBlock` can be used to iterate…

  • CVE-2025-32422HigJun 18, 2026
    risk 0.00cvss —epss 0.00

    AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.63, `StepThroughItemsBlock` can iterate all the contents in a list and send them to `FileStoreBlock` for downloading one by one. Although…