CWE-400: Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
1,952 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-22239 — Email Sending Vulnerability in BLUVOYIX
- CVE-2026-15308 — Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations
- CVE-2023-54365 — Traefik - Denial of Service via HTTP/2 Request Handling
- CVE-2026-28318 — SolarWinds Serv-U Unauthenticated Denial of Service Vulnerability
- CVE-2026-25579 — Navidrome affected by Denial of Service and disk exhaustion via oversized `size` parameter in `/rest/getCoverArt` and `/share/img/<token>` endpoints
- CVE-2026-22542 — DENIAL OF SERVICE FOR CONCURRENT CONNECTIONS ON TELNET
- CVE-2026-22540 — DENIAL OF SERVICE VIA ARP PACKETS
- CVE-2025-64388 — Denial of service through specific packets
- CVE-2025-53371 — DiscordNotifications allows DOS, SSRF, and possible RCE through requests to user-controlled URLs
- CVE-2025-21087 — TMM Vulnerability
- CVE-2025-20058 — BIG-IP message routing vulnerability
- CVE-2026-21485 — iccDEV Undefined Behavior (UB) and Out of Memory in CIccProfile::LoadTag()
- CVE-2025-61595 — MANTRA tx gas limit is not enforced in send hooks
- CVE-2026-68763 — Apache Tomcat: DoS via allocation leak in HTTP/2 backlog tracking when a stream is reset
- CVE-2026-33538 — Parse Server: Denial of service via unindexed database query for unconfigured auth providers
- CVE-2026-33155 — DeepDiff has Memory Exhaustion DoS through SAFE_TO_IMPORT
- CVE-2026-31958 — Tornado has a DoS due to too many multipart parts
- CVE-2025-9466 — ArmorStart® LT - Multiple Denial-of-Service Vulnerabilities
- CVE-2025-9465 — ArmorStart® LT - Multiple Denial-of-Service Vulnerabilities
- CVE-2025-9464 — Rockwell Automation ArmorStart® LT - Multiple Denial-of-Service Vulnerabilities
Recently published
- CVE-2026-22591 — Fast DDS DDSSQLFilter Recursive Parser Stack Exhaustion (Remote DoS)
- CVE-2026-86204 — PocketMine-MP before 5.39.2 Denial of Service via ModalFormResponsePacket
- CVE-2026-86201 — PocketMine-MP before 5.41.1 LogDoS via LoginPacket clientData
- CVE-2025-71418 — PocketMine-MP before 5.25.2 Denial of Service via explode
- CVE-2026-53937 — MCP Kotlin SDK's unbounded line buffer in StdioServerTransport/StdioClientTransport leads to memory exhaustion (DoS)
- CVE-2026-82001 — Acrobat Reader | Uncontrolled Resource Consumption (CWE-400)
- CVE-2026-76000 — ColdFusion | Uncontrolled Resource Consumption (CWE-400)
- CVE-2026-72923 — Microsoft.OpenApi.YamlReader/Readers vulnerable to denial of service via YAML alias expansion
- CVE-2026-86734 — Snipe-IT before 8.7.1 Denial of Service via Unbounded Note Field
- CVE-2026-86135 — Dimension CSRF Vulnerability in Database Snapshot Creation Allows Denial of Service
- CVE-2026-12611 — A client may issue HTTP/2 requests to a Jetty server that result in blocking writes that are never unblocked, eventually
- CVE-2026-86515 — vgmstream txtp txtp_parser.c add_entry resource consumption
- CVE-2026-86513 — java-json-tools jackson-coreutils JSON Pointer parser TreePointer.java TreePointer.tokensFromInput allocation of resources
- CVE-2026-86511 — java-json-tools jackson-coreutils JacksonUtils.java BigDecimal.toPlainString resource consumption
- CVE-2026-86319 — java-json-tools json-patch Patch Operation JsonPatch.java JsonPatch.apply resource consumption
- CVE-2026-86452 — MISP Unauthenticated Mail Endpoints Allow Unbounded Storage Consumption and Request Flooding
- CVE-2022-51018 — PocketMine-MP before 3.26.5 and 4.0.5 Input Validation via Book Pages
- CVE-2026-86421 — ImageMagick before 7.1.2-30 Memory Leak via MSL decoder
- CVE-2026-86420 — ImageMagick before 7.1.2-30 Denial of Service Memory Budget
- CVE-2026-86347 — MISP Missing Authorization on Template File Upload Allows Authenticated Disk Exhaustion
More specific weaknesses
- CWE-1235 — Incorrect Use of Autoboxing and Unboxing for Performance Critical Operations
- CWE-1246 — Improper Write Handling in Limited-write Non-Volatile Memories
- CWE-405 — Amplification
- CWE-770 — Allocation of Resources Without Limits or Throttling
- CWE-771 — Missing Reference to Active Allocated Resource
- CWE-779 — Logging of Excessive Data
- CWE-920 — Improper Restriction of Power Consumption