CWE-400
CVEs classified under CWE-400, newest first.
622 CVEsRSS
CVE-2026-54609High· 8.6QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
CVE-2025-63913High· 7.5An issue was discovered in OpenSBI 1.3 allowing attackers to cause a denial of service via crafted request to the SBI function #2 or the 'Find and configure a matching counter' function of SBI PMU extension.
An issue was discovered in OpenSBI 1.3 allowing attackers to cause a denial of service via crafted request to the SBI function #2 or the 'Find and configure a matching counter' function of SBI PMU extension.
CVE-2026-17501Medium· 5.3A flaw has been found in ggml-org llama.cpp e15efe0
A flaw has been found in ggml-org llama.cpp e15efe0. This vulnerability affects the function transform of the file common/json-schema-to-grammar.cpp of the component JSON-Schema-to-GBNF Conversion. This manipulation causes allocation of …
CVE-2026-55685Medium· 6.5react-router: @remix-run/server-runtime: React Router: Denial of Service via unauthenticated manifest endpoint requests (CVE-2026-55685)
A flaw was found in React Router. An unauthenticated attacker can send targeted requests to the manifest endpoint, leading to a denial of service (DoS). This can put a heavy load on the server, significantly slowing down response times and…
GHSA-68r5-9hpg-7qw9Critical· 9.4OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway
OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway
GHSA-g5vv-q72c-7j78High· 7.5@anephenix/hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion
@anephenix/hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion
GHSA-gm3r-q2wp-hw87HighShescape: Quadratic-time denial of service in the flag-protection
Shescape: Quadratic-time denial of service in the flag-protection
GHSA-hmj8-5xmh-5573High· 7.5libp2p: yamux connection DoS via oversized data frame
libp2p: yamux connection DoS via oversized data frame
CVE-2026-44907High· 7.5react-server-dom: Denial of Service in Server Functions
react-server-dom: Denial of Service in Server Functions
GHSA-v74w-7mr3-4qg3High· 7.5Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion
Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion
GHSA-r292-9mhp-454mMedium· 5.3node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection
node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection
CVE-2026-55594Medium· 5.3ImageMagick: Stack Overflow in MVG decoder due to missing depth check.
ImageMagick: Stack Overflow in MVG decoder due to missing depth check.
CVE-2026-55595Medium· 4.7ImageMagick: Infinite Loop in connected-components when providing invalid arguments
ImageMagick: Infinite Loop in connected-components when providing invalid arguments
GHSA-rvhp-75f6-9jqhLow· 3.3ImageMagick: Policy Bypass possible with matrix-backed operations
ImageMagick: Policy Bypass possible with matrix-backed operations
GHSA-qh5g-q395-cx4jLow· 3.7ImageMagick: Heap-use-after-free via XMP profile could result in a crash
ImageMagick: Heap-use-after-free via XMP profile could result in a crash
CVE-2026-14257High· 7.5brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function (CVE-2026-14257)
A flaw was found in brace-expansion. A remote attacker can exploit this vulnerability by providing specially crafted input to the expand() function, which can lead to excessive memory consumption. This can cause a denial of service (DoS) b…
CVE-2026-59936Highpypdf: Possible infinite loop for not terminated inline images
pypdf: Possible infinite loop for not terminated inline images
CVE-2026-59932High· 7.5PHPSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion
PHPSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion
CVE-2026-59933High· 7.5PHPSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion
PHPSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion
CVE-2026-59937Mediumpypdf: Possible long runtimes for repeated malformed cross-reference entries
pypdf: Possible long runtimes for repeated malformed cross-reference entries
CVE-2026-59941MediumPoCDompdf: Uncontrolled resource consumption based on declared BMP dimensions
Dompdf: Uncontrolled resource consumption based on declared BMP dimensions
CVE-2026-59942MediumDompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps
Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps
CVE-2024-7708High· 7.5Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requests
Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requests
CVE-2026-63136Medium· 6.5Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130)
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A user with search privileges can submit a specially crafted search request that causes a data node to exhau…
CVE-2026-56145Medium· 6.5Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130)
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authenticated user with permission to execute EQL sequence queries against an index they co…
CVE-2026-60647High· 7.1Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management)
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low priv…
CVE-2026-60411Medium· 6.5Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: ttcserver)
Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: ttcserver). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows unauthenticated attack…
CVE-2026-60410Medium· 4.3Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator)
Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileg…
CVE-2026-60404Medium· 6.5Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator)
Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileg…
CVE-2026-60403Medium· 6.5Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator)
Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileg…