VulnSea

CWE-400

CVEs classified under CWE-400, newest first.

622 CVEsRSS

CVE-2026-60399Medium· 6.5
2mo ago

Vulnerability in Oracle GoldenGate (component: Receiver Service Executable)

Vulnerability in Oracle GoldenGate (component: Receiver Service Executable). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows low privileged attacker wi…

▾ Sunlitoracle · goldengateEPSS 0.42%via NVD
CVE-2026-56819High· 7.5PoC
2mo ago

io.netty/netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak (CVE-2026-56819)

A flaw was found in Netty, a network application framework. A remote, unauthenticated attacker can exploit this vulnerability by sending specially crafted HTTP/2 DATA frames to applications that use Netty and have HTTP/2 content decompress…

▾ MidnightRed Hat · Red Hat OpenShift Dev Spaces 3.30EPSS 0.66%via CSAF
CVE-2026-55851High· 7.5
2mo ago

io.netty/netty-codec-haproxy: Netty codec-haproxy: Denial of Service via crafted PROXY protocol v2 message (CVE-2026-55851)

A flaw was found in Netty's codec-haproxy module. A remote attacker could exploit a vulnerability in the HAProxyMessageDecoder by sending a specially crafted PROXY protocol v2 message. This leads to unbounded buffer accumulation, causing a…

▾ TwilightRed Hat · OpenShift ServerlessEPSS 0.63%via CSAF
CVE-2026-56745High· 7.5
2mo ago

netty: io.netty/netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec (CVE-2026-56745)

A flaw was found in Netty. A remote attacker can exploit a vulnerability in the `SpdyHttpDecoder` handler of Netty's SPDY-to-HTTP codec. When processing a client-initiated `SYN_STREAM` frame, the decoder fails to release allocated memory i…

▾ TwilightRed Hat · Red Hat JBoss EAP 8.1 for RHEL 8EPSS 0.63%via CSAF
CVE-2026-56816High· 7.5
2mo ago

io.netty:netty-codec-http3: Netty: Denial of Service due to uncontrolled memory buffering in HTTP/3 (CVE-2026-56816)

A flaw was found in Netty. An unauthenticated remote attacker can exploit a vulnerability in Netty's `Http3FrameCodec` by sending specially crafted HTTP/3 reserved frames with excessive payload lengths. This can lead to uncontrolled memory…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.64%via CSAF
CVE-2026-56657Medium· 6.2
2mo ago

Gitea SSH Key Parser Denial of Service

Gitea SSH Key Parser Denial of Service

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.17%via OSV
CVE-2026-59880High
2mo ago

Immutabl: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set

Immutabl: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set

▾ Twilightimmutable · immutableEPSS 0.66%via GHSA
CVE-2026-59884High· 7.5
2mo ago

pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs

pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs

▾ Twilightpyasn1 · pyasn1EPSS 0.62%via OSV
CVE-2026-55831High· 7.5
2mo ago

io.netty/netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing (CVE-2026-55831)

A flaw was found in Netty, a network application framework. A remote attacker, by sending a specially crafted SPDY/3.1 SETTINGS frame, could cause the SPDY SETTINGS decoder to create a large number of map entries. This excessive processing…

▾ TwilightRed Hat · Red Hat JBoss EAP 8.1 for RHEL 8EPSS 0.66%via CSAF
CVE-2026-55833High· 7.5
2mo ago

netty: io.netty/netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification (CVE-2026-55833)

A flaw was found in Netty, a network application framework. A remote attacker could exploit a vulnerability in the SPDY header decoding process. By sending a specially crafted, small compressed header block, the attacker can cause it to ex…

▾ TwilightRed Hat · Red Hat JBoss EAP 8.1 for RHEL 8EPSS 0.66%via CSAF
GHSA-mwf2-3pr3-8698Medium
2mo ago

Axios: HTTP/2 streamed uploads bypass `maxBodyLength`

Axios: HTTP/2 streamed uploads bypass `maxBodyLength`

▾ Sunlitaxios · axiosvia GHSA
GHSA-pmv8-rq9r-6j72Medium
2mo ago

Axios: Deep formToJSON Key Recursion Can Cause Denial of Service

Axios: Deep formToJSON Key Recursion Can Cause Denial of Service

▾ Sunlitaxios · axiosvia GHSA
GHSA-42h9-826w-cgv3Medium
2mo ago

Axios: Excessive recursion in formDataToJSON can cause denial of service

Axios: Excessive recursion in formDataToJSON can cause denial of service

▾ Sunlitaxios · axiosvia GHSA
CVE-2026-59173None
2mo ago

Uncontrolled Resource Consumption vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.1.13, from 10.0.0 through 10.1.2. Users are recommended to upgrade to version 9.1.14 or 10.1.3, wh…

Uncontrolled Resource Consumption vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.1.13, from 10.0.0 through 10.1.2. Users are recommended to upgrade to version 9.1.14 or 10.1.3, wh…

▾ SunlitEPSS 0.74%via NVD
CVE-2026-50274High· 7.5
2mo ago

github.com/DataDog/dd-trace-go: Datadog dd-trace-go: Denial of Service via malicious baggage headers (CVE-2026-50274)

A flaw was found in Datadog dd-trace-go, a Go client library. A remote, unauthenticated attacker can exploit this vulnerability by sending a request with a specially crafted baggage header containing an arbitrarily large number of key-valu…

▾ TwilightRed Hat · github.com/DataDog/dd-trace-goEPSS 0.79%via CSAF
CVE-2026-44891High· 7.5
2mo ago

io.netty/netty-codec-stomp: Netty: Denial of Service vulnerability in STOMP decoder (CVE-2026-44891)

A flaw was found in Netty, a network application framework, specifically within the StompSubframeDecoder component. This vulnerability allows a remote attacker to cause a denial of service (DoS) by sending a large number of small headers. …

▾ TwilightRed Hat · Red Hat JBoss Enterprise Application Platform 7EPSS 0.73%via CSAF
CVE-2026-50271High· 7.5
2mo ago

dd-trace-py: Improper parsing of W3C baggage headers may lead to DoS

dd-trace-py: Improper parsing of W3C baggage headers may lead to DoS

▾ Twilightddtrace · ddtraceEPSS 0.79%via OSV
CVE-2026-50272High· 7.5
2mo ago

dd-trace-js: Improper parsing of W3C baggage headers may lead to DoS

dd-trace-js: Improper parsing of W3C baggage headers may lead to DoS

▾ Twilightdd-trace · dd-traceEPSS 0.79%via GHSA
CVE-2026-50273High· 7.5
2mo ago

dd-trace-dotnet: Improper parsing of W3C baggage headers may lead to DoS

dd-trace-dotnet: Improper parsing of W3C baggage headers may lead to DoS

▾ TwilightDatadog · Datadog.TraceEPSS 0.79%via GHSA
GHSA-xg43-5579-qw6vMedium· 6.5
2mo ago

adawolfa/isdoc: Uncontrolled resource consumption (decompression bomb) when reading untrusted ISDOCX or PDF files

adawolfa/isdoc: Uncontrolled resource consumption (decompression bomb) when reading untrusted ISDOCX or PDF files

▾ Sunlitadawolfa · adawolfa/isdocvia GHSA
CVE-2026-54463Medium
2mo ago

websocket-driver: Memory exhaustion via abuse of protocol length headers

websocket-driver: Memory exhaustion via abuse of protocol length headers

▾ Sunlitwebsocket-driver · websocket-driverEPSS 0.49%via GHSA
CVE-2026-54465Medium
2mo ago

websocket-driver: Memory exhaustion in HTTP header parser

websocket-driver: Memory exhaustion in HTTP header parser

▾ Sunlitwebsocket-driver · websocket-driverEPSS 0.49%via GHSA
CVE-2026-49799Medium· 6.5
2mo ago

Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability

Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 1.1%via CVEORG
CVE-2026-58627High· 7.5
2mo ago

Windows DHCP Server Denial of Service Vulnerability

Uncontrolled resource consumption in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 1.2%via CVEORG
CVE-2026-59885High· 7.5
2mo ago

pyasn1: python-pyasn1: pyasn1: Denial of Service via crafted ASN.1 OBJECT IDENTIFIER (CVE-2026-59885)

A flaw was found in pyasn1, a Python library for Abstract Syntax Notation One (ASN.1). The BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the number of arcs. A remote attacker cou…

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.62%via CSAF
CVE-2026-59886High· 7.5
2mo ago

pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values (CVE-2026-59886)

A remote attacker can exploit this by providing specially crafted BER/CER/DER-encoded ASN.1 data with a large exponent in the REAL value. When the application subsequently prints, logs, compares, or performs arithmetic on the decoded value…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream EUS (v.9.6)EPSS 0.62%via CSAF
CVE-2026-59200High· 7.5
2mo ago

Pillow: Pillow: Denial of service via crafted PDF stream (CVE-2026-59200)

A flaw was found in Pillow, a Python imaging library. A remote attacker could exploit a vulnerability in the PdfParser.PdfStream.decode() function when processing a crafted FlateDecode PDF stream. By providing a specially designed PDF file…

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.66%via CSAF
CVE-2026-50653High· 7.5
2mo ago

Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.

Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.

▾ TwilightMicrosoft · Azure Active DirectoryEPSS 1.2%via NVD
CVE-2026-54448High
2mo ago

Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser

Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser

▾ Twilightaquasecurity · github.com/aquasecurity/trivyEPSS 0.44%via GHSA
CVE-2026-49477High· 7.5
2mo ago

soupsieve: Soupsieve: Denial of Service via crafted CSS selector strings (CVE-2026-49477)

A flaw was found in soupsieve, a CSS selector library. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by supplying specially crafted, untrusted CSS selector strings. The flaw occurs due to a regular expressi…

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.64%via CSAF
CWE-400 vulnerabilities (CVEs) — page 14 · VulnSea