Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-400'

View all threats tagged with 'cwe-400'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-400

Threats Tagged 'cwe-400'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-16265: CWE-400 Uncontrolled Resource Consumption in WP MapsCVE-2026-16265
0

The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not restrict the operation it dispatches, allowing users with a Subscriber account to trigger uncontrolled recursion that exhausts server resources, resulting in a Denial of Service.

Join the discussion
CVE-2026-48834: CWE-400 Uncontrolled Resource Consumption in Apache Software Foundation Apache AnswerCVE-2026-48834
0

CVE-2026-48834 is a high-severity vulnerability in Apache Answer up to version 2.0.1. It involves improper handling of length parameter inconsistencies in the Accept-Language header, allowing unauthenticated attackers to cause denial of service by triggering excessive CPU consumption during parsing. The issue is fixed in version 2.0.2.

Join the discussion
CVE-2026-67864: n/aCVE-2026-67864
0

A denial of service vulnerability exists in open62541 version 1.5.5 and earlier. This issue arises from the NodeManagement type-instantiation logic, allowing a remote attacker to cause service disruption without requiring authentication or user interaction.

Join the discussion
CVE-2026-67872: n/aCVE-2026-67872
0

Systerel S2OPC version 1.7.3 contains a vulnerability that allows a remote attacker to cause a denial of service by exploiting the event monitored-item queue resize handling. This issue does not affect confidentiality or integrity but results in service disruption. The vulnerability is identified as CWE-400, indicating a resource exhaustion problem. No patch or remediation details are currently provided.

Join the discussion
CVE-2026-70646: CWE-400: Uncontrolled Resource Consumption in vovchic17 aiosendCVE-2026-70646
0

aiosend is a synchronous and asynchronous Crypto Pay API client. Pror to version 3.0.7, `WebhookHandler.feed_update()` deserializes the entire request body before verifying the HMAC signature. This allows an unauthenticated attacker to force expensive parsing of arbitrary JSON payloads that will ultimately be rejected, leading to unnecessary CPU and memory consumption. Version 3.0.7 fixes the issue. Some workarounds are available. Restrict request body size at the reverse proxy or web framework, rate-limit webhook endpoints, and/or reject oversized requests before JSON parsing.

Join the discussion
CVE-2026-64958: CWE-400 Uncontrolled Resource Consumption in Apache Software Foundation Apache CXFCVE-2026-64958
0

An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of service attack on Apache CXF by sending a message with many attachment headers. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.

Join the discussion
CVE-2026-57819: CWE-400 Uncontrolled Resource Consumption in Apache Software Foundation Apache CXFCVE-2026-57819
0

Apache CXF allows to set a limit on the number of form parameters in a JAX-RS message via the "maxFormParameterCount" configuration option. However, no default limit is set which may lead to denial of service attacks when processing  requests with very large numbers of form parameters. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue by using a default limit of 500 parameters.

Join the discussion
CVE-2026-48834: CWE-400 Uncontrolled Resource Consumption in Apache Software Foundation Apache AnswerCVE-2026-48834
0

Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Unauthenticated attackers can cause a denial of service via a specially crafted Accept-Language header that triggers excessive CPU consumption during parsing. Users are recommended to upgrade to version 2.0.2, which fixes the issue.

Join the discussion
CVE-2026-61387: CWE-460 in Eclipse Foundation Eclipse MiloCVE-2026-61387
0

In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting is not exception-safe: if item creation fails with an unchecked error, the server-global reservation is not restored. Deeply nested PubSub ExtensionObjects in a `CreateMonitoredItems` event filter can trigger a `StackOverflowError` during decoding, allowing an unauthenticated remote client to exhaust a finite global monitored-item quota and prevent all clients from creating new monitored items until restart. Existing monitored items and other server functions remain unaffected.

Join the discussion
CVE-2026-58045: CWE-400 Uncontrolled Resource Consumption in nodejs nodeCVE-2026-58045
0

A flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigger a reachable assertion in the synchronous `node:zlib` APIs, causing the entire process to crash. All 11 synchronous zlib functions are affected. Repeated exploitation of this condition can result in a denial of service. This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.

Join the discussion

Showing 1 to 10 of 86 results

Filters:Tag: cwe-400
Page 1 of 9
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses