CWE-400Class7 in KEV

Uncontrolled Resource Consumption

Draft in the CWE catalog · 2,024 CVEs mapped

2,024
CVEs mapped
7
In KEV
6.9
Median CVSS
What it is

The product does not properly control the allocation and maintenance of a limited resource.

Recent examples
6.5cvss
CVE-2026-86255

CVE-2026-86255 - MEDIUM Severity Vulnerability

wger before 2.5 fails to validate the maximum duration of routine date ranges, allowing authenticated users to create routines spanning arbitrarily long periods. Attackers can trigger the date_sequence computation via routine detail endpoints, forcing the server to iterate thousands of times per request and exhaust worker threads, denying service to legitimate users.

MEDIUMno explanation yet
epss
7.5cvss
CVE-2026-86250

CVE-2026-86250 - HIGH Severity Vulnerability

h3 versions before 2.0.1-rc.18 fail to validate the chunk count parsed from user-controlled cookie values in setChunkedCookie() and deleteChunkedCookie() functions. Attackers can send a crafted cookie header with an extremely large chunk count to trigger an O(n²) cleanup loop that hangs the server process.

HIGHno explanation yet
epss
6.5cvss
CVE-2020-37277

CVE-2020-37277 - MEDIUM Severity Vulnerability

PocketMine-MP versions before 3.15.4 contain a denial of service vulnerability in the InventoryTransaction component's findResultItem() method. Malicious clients can send specially crafted InventoryTransactionPackets with multiple conflicting pathways to cause exponential processing complexity, freezing the server.

MEDIUMno explanation yet
epss
The record
Technical detail
CWE ID
CWE-400
Abstraction
Class
Structure
Simple
Status
Draft
References (5)