VulnSea

CWE-400

CVEs classified under CWE-400, newest first.

623 CVEsRSS

CVE-2023-54365High· 7.5
3mo ago

Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inherited from the Go standard library's HTTP/2 implementation (CVE-2023-44487 / CVE-2023-39325, the 'Rapid Reset' techniqu…

Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inherited from the Go standard library's HTTP/2 implementation (CVE-2023-44487 / CVE-2023-39325, the 'Rapid Reset' techniqu…

▾ Twilighttraefik · traefikEPSS 0.77%via NVD
CVE-2026-52814Medium
3mo ago

Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion)

Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion)

▾ Sunlitgogs · gogs.io/gogsEPSS 0.55%via GHSA
CVE-2026-50193High· 7.5
3mo ago

jackson-databind: Jackson-databind: Denial of Service via deeply nested JSON processing (CVE-2026-50193)

A flaw was found in jackson-databind, a general-purpose data-binding library for Jackson Data Processor. A remote attacker can exploit this vulnerability by sending deeply nested JSON (JavaScript Object Notation) data to a service that rea…

▾ TwilightRed Hat · Red Hat JBoss EAP 7.4 ELS for RHEL 8EPSS 0.62%via CSAF
CVE-2026-42127High· 7.5
3mo ago

The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads

The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of serv…

▾ Twilightgrafana · grafanaEPSS 0.43%via NVD
GHSA-74p7-6h78-gw8pHigh
3mo ago

skillctl: argument injection, path traversal in --dest, FIFO/device DoS, hardlink exfiltration, and commit-trailer forgery

skillctl: argument injection, path traversal in --dest, FIFO/device DoS, hardlink exfiltration, and commit-trailer forgery

▾ Twilightskillctl · skillctlvia GHSA
CVE-2026-47262Medium
3mo ago

containerd image-triggered runtime DoS via unbounded group parsing

containerd image-triggered runtime DoS via unbounded group parsing

▾ Sunlitcontainerd · github.com/containerd/containerd/v2EPSS 0.26%via GHSA
CVE-2026-54772High· 7.5
3mo ago

CoreWCF: Pre-authentication infinite-loop CPU exhaustion in CoreWCF net.tcp / net.pipe / net.uds framing handshake

CoreWCF: Pre-authentication infinite-loop CPU exhaustion in CoreWCF net.tcp / net.pipe / net.uds framing handshake

▾ TwilightCoreWCF · CoreWCF.NetFramingBaseEPSS 0.85%via GHSA
GHSA-8823-qg2x-pv9fHigh· 7.5
3mo ago

Ultimate Sitemap Parser (USP): Gzip Decompression Bomb Bypasses Sitemap Size Limit

Ultimate Sitemap Parser (USP): Gzip Decompression Bomb Bypasses Sitemap Size Limit

▾ Twilightultimate-sitemap-parser · ultimate-sitemap-parservia GHSA
CVE-2026-55446High· 7.5
3mo ago

Langflow: Unauthenticated DoS through multipart form boundary file upload

Langflow: Unauthenticated DoS through multipart form boundary file upload

▾ Twilightlangflow · langflowEPSS 0.58%via GHSA
GHSA-xcqx-9jf5-w339High· 7.5
3mo ago

SearXNG MCP Server: Unbounded Response Body Read Bypasses URL Size Limit in `web_url_read`

SearXNG MCP Server: Unbounded Response Body Read Bypasses URL Size Limit in `web_url_read`

▾ Twilightmcp-searxng · mcp-searxngvia GHSA
GHSA-4xgf-cpjx-pc3jMedium· 5.3
3mo ago

pydantic-settings: NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size

pydantic-settings: NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size

▾ Sunlitpydantic-settings · pydantic-settingsvia GHSA
GHSA-2r2c-cx56-8933High· 7.5
3mo ago

JLine3 Telnet server: Unauthenticated Remote DoS via Unbounded Telnet NAWS Terminal Geometry

JLine3 Telnet server: Unauthenticated Remote DoS via Unbounded Telnet NAWS Terminal Geometry

▾ Twilightjline · org.jline:jline-remote-telnetvia GHSA
GHSA-47qp-hqvx-6r3fHigh· 7.5
3mo ago

JLine3 Telnet server: Unauthenticated Remote Memory Exhaustion via Unbounded Telnet NEW-ENVIRON Variables

JLine3 Telnet server: Unauthenticated Remote Memory Exhaustion via Unbounded Telnet NEW-ENVIRON Variables

▾ Twilightjline · org.jline:jline-remote-telnetvia GHSA
CVE-2026-9675High· 7.5
3mo ago

undici WebSocket client vulnerable to denial of service via cumulative fragment bypass

undici WebSocket client vulnerable to denial of service via cumulative fragment bypass

▾ Twilightundici · undiciEPSS 0.49%via GHSA
GHSA-jm82-fx9c-mx94Medium
3mo ago

pypdf: Missing stream length values ignore defined limits

pypdf: Missing stream length values ignore defined limits

▾ Sunlitpypdf · pypdfvia GHSA
GHSA-3prj-6hqw-cm82High
3mo ago

PHP JWT Library: PBES2-HS*+A*KW unwrap accepts an unbounded p2c iteration count, enabling CPU-amplification denial of service

PHP JWT Library: PBES2-HS*+A*KW unwrap accepts an unbounded p2c iteration count, enabling CPU-amplification denial of service

▾ Twilightweb-token · web-token/jwt-libraryvia GHSA
CVE-2026-48779High· 7.5PoC
3mo ago

ws is an open source WebSocket client and server for Node.js

ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7.0.0 up to 7.5.11, and from 8.0.0 up to 8.21.0 are affected by a memory exhaustion DoS v…

▾ Midnightws_project · wsEPSS 0.93%via NVD
CVE-2026-55450Critical· 9.3PoC
3mo ago

Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak

Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak

▾ Abyssallangflow · langflowEPSS 1.2%via GHSA
CVE-2026-12151High· 7.5
3mo ago

undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames (CVE-2026-12151)

A flaw was found in undici. A malicious WebSocket server can exploit this by streaming numerous small or empty continuation frames. This can bypass per-frame and cumulative-size validation, leading to unbounded memory growth in the client …

▾ TwilightRed Hat · Red Hat Openshift Data Foundation 4.20EPSS 0.79%via CSAF
CVE-2026-49461Medium
3mo ago

pypdf: Possible large memory usage for form XObjects during text extraction

pypdf: Possible large memory usage for form XObjects during text extraction

▾ Sunlitpypdf · pypdfEPSS 0.17%via GHSA
CVE-2026-50171High
3mo ago

@angular/common: Denial of Service (DoS) via OOM in Number Formatting (digitsInfo)

@angular/common: Denial of Service (DoS) via OOM in Number Formatting (digitsInfo)

▾ Twilightangular · @angular/commonEPSS 0.26%via GHSA
CVE-2026-54268High
3mo ago

@angular/common: Denial of Service (DoS) via OOM in Date Formatting (formatDate)

@angular/common: Denial of Service (DoS) via OOM in Date Formatting (formatDate)

▾ Twilightangular · @angular/commonEPSS 0.58%via GHSA
CVE-2026-48525Medium· 5.3
3mo ago

PyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload segment in b64=false detached JWS

PyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload segment in b64=false detached JWS

▾ Sunlitpyjwt · pyjwtEPSS 0.41%via OSV
CVE-2026-48125Medium· 5.3
3mo ago

UAParser.js: Unbounded `Sec-CH-UA-Model` parsing can trigger ReDoS in `withClientHints()`

UAParser.js: Unbounded `Sec-CH-UA-Model` parsing can trigger ReDoS in `withClientHints()`

▾ Sunlitua-parser-js · ua-parser-jsEPSS 0.52%via GHSA
CVE-2026-53539High· 7.5
3mo ago

python-multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of service

python-multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of service

▾ Twilightpython-multipart · python-multipartEPSS 0.46%via OSV
CVE-2026-48988Medium· 5.3
3mo ago

markdown-it: Quadratic complexity DoS in smartquotes rule via replaceAt string operations

markdown-it: Quadratic complexity DoS in smartquotes rule via replaceAt string operations

▾ Sunlitmarkdown-it · markdown-itEPSS 0.43%via GHSA
CVE-2026-5079High· 7.5
3mo ago

multer: Multer: Denial of Service via deeply nested field names in multipart form data (CVE-2026-5079)

A flaw was found in Multer. A remote attacker can exploit this vulnerability by sending a single HTTP request with crafted multipart form data containing deeply nested field names. This can force the allocation of deeply nested object stru…

▾ TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.49%via CSAF
CVE-2026-50645High· 7.5
3mo ago

There is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache CXF, which can lead to uncontrolled resource consumption or a denial of service attack. Users are recommended to upg…

There is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache CXF, which can lead to uncontrolled resource consumption or a denial of service attack. Users are recommended to upg…

▾ Twilightapache · cxfEPSS 0.74%via NVD
CVE-2026-47244Medium· 5.3
3mo ago

netty-codec-http2: Netty: Denial of Service via uncontrolled HTTP/2 concurrent streams (CVE-2026-47244)

A flaw was found in Netty, a network application framework. A remote attacker can exploit this vulnerability by sending a large number of HTTP/2 stream requests to a Netty HTTP/2 server. If the server does not explicitly limit concurrent s…

▾ SunlitRed Hat · OpenShift ServerlessEPSS 0.51%via CSAF
CVE-2026-28980High
3mo ago

SwiftNIO NIOHTTP1: HTTPDecoder accepts unbounded HTTP/1 header blocks, enabling remote DoS

SwiftNIO NIOHTTP1: HTTPDecoder accepts unbounded HTTP/1 header blocks, enabling remote DoS

▾ Twilightapple · github.com/apple/swift-niovia GHSA
CWE-400 vulnerabilities (CVEs) — page 16 · VulnSea