VulnSea

CWE-400

CVEs classified under CWE-400, newest first.

622 CVEsRSS

CVE-2026-45498Medium· 4.0CISA KEV0dayPoC
4mo ago

Microsoft Defender Denial of Service Vulnerability

Microsoft Defender Denial of Service Vulnerability

▾ Midnightmicrosoft · defender_antimalware_platformEPSS 1.3%via NVD
CVE-2026-8968High· 7.5
4mo ago

Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component

Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

▾ Twilightmozilla · firefoxEPSS 0.53%via NVD
CVE-2026-8769Low· 4.3
4mo ago

@ai-sdk/provider-utils has an Uncontrolled Resource Consumption issue

@ai-sdk/provider-utils has an Uncontrolled Resource Consumption issue

▾ Sunlitai-sdk · @ai-sdk/provider-utilsEPSS 0.73%via GHSA
CVE-2026-44248Medium· 5.3⚖ disputed
4mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any message size limit is applied. Specifically, in MqttDec…

▾ Sunlitnetty · nettyEPSS 0.72%via NVD
CVE-2026-42579High· 7.5PoC
4mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirec…

▾ Midnightnetty · nettyEPSS 0.85%via NVD
CVE-2026-42587High· 7.5PoC
4mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb at…

▾ Midnightnetty · nettyEPSS 1.0%via NVD
CVE-2026-34665High· 7.5
4mo ago

CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service

CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability t…

▾ Twilightadobe · c2paEPSS 0.90%via NVD
CVE-2026-34651High· 7.5
4mo ago

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could e…

▾ Twilightadobe · commerceEPSS 0.90%via NVD
CVE-2026-34650High· 7.5
4mo ago

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could e…

▾ Twilightadobe · commerceEPSS 0.90%via NVD
CVE-2026-34649High· 7.5
4mo ago

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could e…

▾ Twilightadobe · commerceEPSS 0.90%via NVD
CVE-2026-34648High· 7.5
4mo ago

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could e…

▾ Twilightadobe · commerceEPSS 1.0%via NVD
CVE-2026-42006Medium· 4.3
4mo ago

An attacker can cause uncontrolled memory usage with excessive bracing over IMAP

An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomplete, only blocking one way of doing this, so there was still another way left open. In particular, the fix was for clo…

▾ Sunlitdovecot · dovecotEPSS 0.82%via NVD
CVE-2026-44241High· 7.5
4mo ago

Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications

Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. From 4.3.0 to before 4.10.22, 3.10.6, and 3.8.14, TimeConverterRegistrar caches DateTimeFormatter instances in …

▾ TwilightEPSS 0.72%via NVD
CVE-2026-43653Medium· 6.2
4mo ago

The issue was addressed with improved memory handling

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.8, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5. An attacker on the local networ…

▾ Sunlitapple · ipadosEPSS 0.18%via NVD
CVE-2026-32686Medium· 6.9PoC
4mo ago

Uncontrolled Resource Consumption vulnerability in ericmj decimal allows unauthenticated remote Denial of Service. The decimal library does not bound the exponent on parsed input

Uncontrolled Resource Consumption vulnerability in ericmj decimal allows unauthenticated remote Denial of Service. The decimal library does not bound the exponent on parsed input. Storing a decimal with a very large exponent (e.g. Decim…

▾ Twilightericmj · decimalEPSS 0.34%via NVD
CVE-2026-23870High· 7.5PoC
4mo ago

A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to server crashes, out-of-memory exceptions or excessive CPU usage; affecting the following pac…

A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to server crashes, out-of-memory exceptions or excessive CPU usage; affecting the following pac…

▾ Midnightfacebook · react-server-dom-parcelEPSS 1.5%via NVD
CVE-2026-42154High· 7.5PoC
4mo ago

Prometheus is an open-source monitoring system and time series database

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a snappy-compressed request body before…

▾ Midnightprometheus · prometheusEPSS 0.89%via NVD
CVE-2026-21728High· 7.5
5mo ago

Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy. Mitigation can be done by setting max_result_limit in the search config, e.g

Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy. Mitigation can be done by setting max_result_limit in the search config, e.g. to …

▾ Twilightgrafana · tempoEPSS 0.64%via NVD
CVE-2026-6844Medium· 5.5
5mo ago

A flaw was found in the `readelf` utility of the binutils package

A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file. One vulnerability, …

▾ Sunlitgnu · binutilsEPSS 0.15%via NVD
CVE-2026-34282High· 7.5
5mo ago

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking)

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 8u481-perf, 11.0.30, 17.0.18, 21.…

▾ Twilightoracle · jreEPSS 0.89%via NVD
CVE-2026-3505High· 7.5
5mo ago

Allocation of resources without limits or throttling, Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc

Allocation of resources without limits or throttling, Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpg on all (pg modules). This vulnerability is associated with program files AEADEncData…

▾ TwilightLegion of the Bouncy Castle Inc. · bcpgEPSS 0.88%via NVD
CVE-2026-40192High· 7.5
5mo ago

Pillow is a Python imaging library

Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file coul…

▾ Twilightpython · pillowEPSS 0.87%via NVD
CVE-2026-26171High· 7.5
5mo ago

.NET Denial of Service Vulnerability

Uncontrolled resource consumption in .NET allows an unauthorized attacker to deny service over a network.

▾ TwilightMicrosoft · .NET 10.0EPSS 2.3%via CVEORG
CVE-2026-27307Low· 2.4
5mo ago

ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service

ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. A high-privileged attacker could exploit this vulnerability and exhaust …

▾ Sunlitadobe · coldfusionEPSS 0.36%via NVD
CVE-2026-33116High· 7.5
5mo ago

Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a network.

Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a network.

▾ Twilightmicrosoft · .netEPSS 2.4%via NVD
CVE-2026-23869High· 7.5PoC
5mo ago

A denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack and react-server-dom-webpack (versions 19.0.0 through 19.0.4, 19.1.0 through 19.1.…

A denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack and react-server-dom-webpack (versions 19.0.0 through 19.0.4, 19.1.0 through 19.1.…

▾ MidnightEPSS 1.6%via NVD
CVE-2026-34404High· 7.5
6mo ago

Nuxt OG Image generates OG Images with Vue templates in Nuxt

Nuxt OG Image generates OG Images with Vue templates in Nuxt. Prior to version 6.2.5, the image‑generation component by the URI: /_og/d/ (and, in older versions, /og-image/) contains a Denial of Service (DoS) vulnerability. The issue ari…

▾ Twilightnuxt · og_imageEPSS 0.46%via NVD
CVE-2026-4926High· 7.5
6mo ago

Impact: A bad regular expression is generated any time you have multiple sequential optional groups (curly brace syntax), such as `{a}{b}{c}:z`

Impact: A bad regular expression is generated any time you have multiple sequential optional groups (curly brace syntax), such as `{a}{b}{c}:z`. The generated regex grows exponentially with the number of groups, causing denial of servic…

▾ Twilightpillarjs · path-to-regexpEPSS 0.89%via NVD
CVE-2026-23940Medium· 6.5
6mo ago

Uncontrolled Resource Consumption vulnerability in hexpm hexpm/hexpm allows Excessive Allocation. Publishing an oversized package can cause Hex.pm to run out of memory while extracting the uploaded package tarball

Uncontrolled Resource Consumption vulnerability in hexpm hexpm/hexpm allows Excessive Allocation. Publishing an oversized package can cause Hex.pm to run out of memory while extracting the uploaded package tarball. This can terminate th…

▾ Sunlithex · hexpmEPSS 0.44%via NVD
CVE-2026-31958High· 7.5⚖ disputed
6mo ago

Tornado is a Python web framework and asynchronous networking library

Tornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only limit on the number of parts in multipart/form-data is the max_body_size setting (default 100MB). Since parsing occurs…

▾ Twilighttornadoweb · tornadoEPSS 0.49%via NVD
CWE-400 vulnerabilities (CVEs) — page 18 · VulnSea