Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-407'

View all threats tagged with 'cwe-407'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-407

Threats Tagged 'cwe-407'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-49460: CWE-407: Inefficient Algorithmic Complexity in py-pdf pypdfCVE-2026-49460
0

CVE-2026-49460 is a medium severity vulnerability in the pypdf library prior to version 6.12.2. It involves inefficient algorithmic complexity triggered by specially crafted PDF files that use the /FlateDecode filter with a PNG predictor, causing long runtimes during processing. This issue has been fixed in version 6.12.2.

Join the discussion
CVE-2026-53539: CWE-400: Uncontrolled Resource Consumption in Kludex python-multipartCVE-2026-53539
0

CVE-2026-53539 is a high-severity vulnerability in Kludex python-multipart prior to version 0.0.30. The issue arises when parsing application/x-www-form-urlencoded bodies that use semicolon (;) as a field separator without ampersands (&). The parser performs an inefficient scan for & on every field iteration, causing quadratic time complexity in CPU usage. This can lead to excessive CPU consumption and potential denial of service when processing crafted requests. The vulnerability is fixed in version 0.0.30.

Join the discussion
CVE-2026-53550: CWE-407: Inefficient Algorithmic Complexity in nodeca js-yamlCVE-2026-53550
0

js-yaml versions prior to 4.2.0 contain an inefficient algorithmic complexity vulnerability in merge-key processing. A crafted YAML document with repeated aliases in a merge sequence can cause quadratic CPU usage, leading to denial of service by blocking the Node.js event loop. This issue is fixed in version 4.2.0.

Join the discussion
CVE-2026-49293: CWE-400: Uncontrolled Resource Consumption in sunnyadn js-tomlCVE-2026-49293
0

js-toml is a TOML parser for JavaScript, fully compliant with the TOML 1.0.0 Spec. Versions up to and including 1.1.0 parse hexadecimal / octal / binary integer literals via a hand-written `parseBigInt` loop that multiplies a `BigInt` accumulator by the radix once per input digit. Each iteration performs a `BigInt * BigInt` operation on an accumulator that grows linearly with the number of digits already consumed, so the whole loop is O(n²) in the literal length. The lexer regex places no upper bound on the literal length, so a single TOML document containing one ~500 kB hex literal pins one CPU core for ~40 seconds on a modern laptop (Apple M-series, Node v22). Memory amplification is bounded but CPU amplification is severe and grows quadratically: doubling the literal length quadruples the work. A caller that invokes `load()` on attacker-controlled TOML (configuration upload endpoints, CI/CD systems ingesting third-party `*.toml`, IDE plugins, build tools) is exposed to a single-request CPU exhaustion DoS. Version 1.1.1 fixes the issue.

Join the discussion
Red Hat Security Advisory: .NET 6.0 security updateCVE-2024-43483
0

.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability

Join the discussion
CVE-2024-43484: CWE-407: Inefficient Algorithmic Complexity in Microsoft .NET 6.0CVE-2024-43484
0

.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability

Join the discussion
CVE-2024-43485: CWE-407: Inefficient Algorithmic Complexity in Microsoft .NET 6.0CVE-2024-43485
0

.NET and Visual Studio Denial of Service Vulnerability

Join the discussion
CVE-2026-41850: CWE-407: Inefficient Algorithmic Complexity in Spring Spring FrameworkCVE-2026-41850
0

Spring Framework versions 5.3.0 through 5.3.48, 6.1.0 through 6.1.27, 6.2.0 through 6.2.18, and 7.0.0 through 7.0.7 are vulnerable to an inefficient algorithmic complexity issue in the Spring Expression Language (SpEL) evaluation. This vulnerability allows an attacker to supply a crafted expression that causes excessive resource consumption, potentially leading to denial of service conditions. The vulnerability is identified as CWE-407 and has a CVSS 3.1 score of 7.5 (high severity). No official patch or remediation guidance is currently provided.

Join the discussion
CVE-2026-3276: CWE-407 in Python Software Foundation CPythonCVE-2026-3276
0

unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs of combining characters with alternating Canonical Combining Class values. This affects all normalization forms.

Join the discussion
rclone-1.74.3-1.1 on GA mediaCVE-2026-27145
0

These are all security issues fixed in the rclone-1.74.3-1.1 package on the GA media of openSUSE Tumbleweed.

Join the discussion

Showing 1 to 10 of 15 results

Filters:Tag: cwe-407
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses