Threats Tagged 'cwe-407'
View all threats tagged with 'cwe-407'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-407'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-49460: CWE-407: Inefficient Algorithmic Complexity in py-pdf pypdfCVE-2026-49460 0 CVE-2026-49460 is a medium severity vulnerability in the pypdf library prior to version 6.12.2. It involves inefficient algorithmic complexity triggered by specially crafted PDF files that use the /FlateDecode filter with a PNG predictor, causing long runtimes during processing. This issue has been fixed in version 6.12.2. Join the discussion | CVE Database V5 | 06/22/2026, 20:28:16 UTC Added: 06/22/2026, 20:54:13 UTC |
CVE-2026-53539: CWE-400: Uncontrolled Resource Consumption in Kludex python-multipartCVE-2026-53539 0 CVE-2026-53539 is a high-severity vulnerability in Kludex python-multipart prior to version 0.0.30. The issue arises when parsing application/x-www-form-urlencoded bodies that use semicolon (;) as a field separator without ampersands (&). The parser performs an inefficient scan for & on every field iteration, causing quadratic time complexity in CPU usage. This can lead to excessive CPU consumption and potential denial of service when processing crafted requests. The vulnerability is fixed in version 0.0.30. Join the discussion | CVE Database V5 | 06/22/2026, 16:55:42 UTC Added: 06/22/2026, 17:39:38 UTC |
CVE-2026-53550: CWE-407: Inefficient Algorithmic Complexity in nodeca js-yamlCVE-2026-53550 0 js-yaml versions prior to 4.2.0 contain an inefficient algorithmic complexity vulnerability in merge-key processing. A crafted YAML document with repeated aliases in a merge sequence can cause quadratic CPU usage, leading to denial of service by blocking the Node.js event loop. This issue is fixed in version 4.2.0. Join the discussion | CVE Database V5 | 06/22/2026, 14:59:14 UTC Added: 06/22/2026, 15:39:22 UTC |
CVE-2026-49293: CWE-400: Uncontrolled Resource Consumption in sunnyadn js-tomlCVE-2026-49293 0 js-toml is a TOML parser for JavaScript, fully compliant with the TOML 1.0.0 Spec. Versions up to and including 1.1.0 parse hexadecimal / octal / binary integer literals via a hand-written `parseBigInt` loop that multiplies a `BigInt` accumulator by the radix once per input digit. Each iteration performs a `BigInt * BigInt` operation on an accumulator that grows linearly with the number of digits already consumed, so the whole loop is O(n²) in the literal length. The lexer regex places no upper bound on the literal length, so a single TOML document containing one ~500 kB hex literal pins one CPU core for ~40 seconds on a modern laptop (Apple M-series, Node v22). Memory amplification is bounded but CPU amplification is severe and grows quadratically: doubling the literal length quadruples the work. A caller that invokes `load()` on attacker-controlled TOML (configuration upload endpoints, CI/CD systems ingesting third-party `*.toml`, IDE plugins, build tools) is exposed to a single-request CPU exhaustion DoS. Version 1.1.1 fixes the issue. Join the discussion | CVE Database V5 | 06/19/2026, 18:14:20 UTC Added: 06/19/2026, 18:37:16 UTC |
Red Hat Security Advisory: .NET 6.0 security updateCVE-2024-43483 0 .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability Join the discussion | GCVE Database | 10/08/2024, 17:35:46 UTC Added: 06/09/2026, 19:18:57 UTC |
CVE-2024-43484: CWE-407: Inefficient Algorithmic Complexity in Microsoft .NET 6.0CVE-2024-43484 0 .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability Join the discussion | GCVE Database | 10/08/2024, 17:35:46 UTC Added: 06/09/2026, 19:18:57 UTC |
CVE-2024-43485: CWE-407: Inefficient Algorithmic Complexity in Microsoft .NET 6.0CVE-2024-43485 0 .NET and Visual Studio Denial of Service Vulnerability Join the discussion | GCVE Database | 10/08/2024, 17:35:47 UTC Added: 06/09/2026, 19:18:57 UTC |
CVE-2026-41850: CWE-407: Inefficient Algorithmic Complexity in Spring Spring FrameworkCVE-2026-41850 0 Spring Framework versions 5.3.0 through 5.3.48, 6.1.0 through 6.1.27, 6.2.0 through 6.2.18, and 7.0.0 through 7.0.7 are vulnerable to an inefficient algorithmic complexity issue in the Spring Expression Language (SpEL) evaluation. This vulnerability allows an attacker to supply a crafted expression that causes excessive resource consumption, potentially leading to denial of service conditions. The vulnerability is identified as CWE-407 and has a CVSS 3.1 score of 7.5 (high severity). No official patch or remediation guidance is currently provided. Join the discussion | CVE Database V5 | 06/09/2026, 03:51:22 UTC Added: 06/09/2026, 04:48:50 UTC |
CVE-2026-3276: CWE-407 in Python Software Foundation CPythonCVE-2026-3276 0 unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs of combining characters with alternating Canonical Combining Class values. This affects all normalization forms. Join the discussion | CVE Database V5 | 06/03/2026, 14:29:39 UTC Added: 06/03/2026, 15:48:54 UTC |
rclone-1.74.3-1.1 on GA mediaCVE-2026-27145 0 These are all security issues fixed in the rclone-1.74.3-1.1 package on the GA media of openSUSE Tumbleweed. Join the discussion | GCVE Database | 06/08/2026, 00:00:00 UTC Added: 06/03/2026, 01:45:14 UTC |
Showing 1 to 10 of 15 results