Vulnerability index

Browse CVEs

80 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
HIGH 7.5 CVE-2026-73634 Uncontrolled resource consumption vulnerability in Apache Struts. An application that exposes an endpoint collecting Content Security Policy violatio… Struts Fix unknown Fix from $4,9002026-08-15 HIGH 7.5 CVE-2026-73633 Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts. When an application is configured to populate actions from a JSO… Struts No fix yet Fix from $4,9002026-08-14 HIGH 7.5 CVE-2026-57819 Apache CXF allows to set a limit on the number of form parameters in a JAX-RS message via the "maxFormParameterCount" configuration option. However, … Cxf 3.6.12 / 4.1.8+ Fix from $1,9502026-08-06 HIGH 7.5 CVE-2026-64958 An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of service attack on Apache CXF by sending a message with ma… Cxf 3.6.12 / 4.1.8+ Fix from $1,9502026-08-06 HIGH 7.5 CVE-2026-48834 Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Unauthenticate… Answer 2.0.2+ Fix from $1,9502026-08-05 HIGH 8.6 CVE-2026-58182 The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per-instance state. This issue affects Apache Traffic Serv… Traffic Server 9.2.15 / 10.1.4+ Fix from $1,9502026-07-29 HIGH 7.5 CVE-2026-65324 Apache Traffic Server drops the per-stream buffer cap when dechunking HTTP/2 or HTTP/3 responses, letting a slow client exhaust server memory. This … Traffic Server 9.2.15 / 10.1.4+ Fix from $1,9502026-07-29 HIGH 7.5 CVE-2026-58151 Apache Traffic Server can be crashed or driven to resource exhaustion by abusive HTTP/2 framing and flow-control. This issue affects Apache Traffic … Traffic Server 9.2.15 / 10.1.4+ Fix from $1,9502026-07-29 HIGH 7.5 CVE-2026-66299 Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example. This issue affects Apache Tomcat: from 11.0.0-M20 through… Tomcat 9.0.121 / 10.1.58+ Fix from $1,9502026-07-28 HIGH 7.5 CVE-2026-66142 Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested structures, which may lead to … Neethi 3.2.3+ Fix from $1,9502026-07-24 HIGH 7.5 CVE-2026-66143 It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2 via certain crafted policies… Neethi No fix yet Fix from $1,9502026-07-24 HIGH 7.5 CVE-2026-66144 Although remote policy references are not retrieved during policy normalization, if they are manually retrieved via the API it can cause a denial of … Neethi 3.2.3+ Fix from $1,9502026-07-24 HIGH 7.5 CVE-2026-59173 Uncontrolled Resource Consumption vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.1.13, from … Traffic Server 9.2.14 / 10.1.3+ Fix from $1,9502026-07-18 HIGH 7.5 CVE-2026-24012 Uncontrolled Resource Consumption vulnerability in Apache IoTDB.  Some interface fails to impose reasonable limits on the time span and aggregation … Iotdb 2.0.8+ Fix from $1,9502026-07-06 HIGH 7.5 CVE-2026-54428 Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earl… Httpcomponents Core after 5.4.2 Fix from $1,9502026-07-01 HIGH 7.5 CVE-2026-54399 Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlie… Httpcomponents Core after 5.4.2 Fix from $1,9502026-07-01 HIGH 7.5 CVE-2026-50750 Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Following the fix for CVE-2026-4… Activemq Mitigation only Fix from $1,9502026-06-30 HIGH 7.5 CVE-2026-50645 There is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache CXF, which can lead to uncon… Cxf 4.1.7 / 4.2.2+ Fix from $1,9502026-06-12 HIGH 7.5 CVE-2026-49361 Apache Fluss versions prior to 0.9.1 configure the Netty LengthFieldBasedFrameDecoder with Integer.MAX_VALUE as the maximum frame length, allowing un… Fluss 0.9.1+ Fix from $1,9502026-06-01 HIGH 7.3 CVE-2026-43870 Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of CRLF Sequences in… Thrift 0.23.0+ Fix from $1,9502026-05-05 HIGH 7.5 CVE-2026-42403 Apache Neethi does not properly detect circular references in policy definitions. When a WS-Policy document contains circular policy references (wher… Neethi 3.2.2+ Fix from $1,9502026-05-01 HIGH 7.5 CVE-2026-42402 Apache Neethi is vulnerable to a Denial of Service attack through algorithmic complexity in policy normalization. Specially crafted WS-Policy documen… Neethi 3.2.2+ Fix from $1,9502026-05-01 HIGH 7.5 CVE-2026-39304 Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ. ActiveMQ NIO SSL transports do… Activemq 5.19.4 / 6.2.4+ Fix from $1,9502026-04-10 MEDIUM 6.5 CVE-2026-32588 Authenticated DoS over CQL in Apache Cassandra 4.0, 4.1, 5.0 allows authenticated user to raise query latencies via repeated password changes. Users … Cassandra 4.0.20 / 4.1.11+ Fix from $1,6002026-04-07 HIGH 7.5 CVE-2025-48392 A vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.3.3 through 1.3.4, from 2.0.1-beta through 2.0.4. Users are recommended to… Iotdb 2.0.5+ Fix from $1,9502025-09-24 HIGH 7.5 CVE-2025-54472 Unlimited memory allocation in redis protocol parser in Apache bRPC (all versions < 1.14.1) on all platforms allows attackers to crash the service vi… Brpc 1.14.1+ Fix from $1,9502025-08-14 MEDIUM 5.6 CVE-2025-48795 Apache CXF stores large stream based messages as temporary files on the local filesystem. A bug was introduced which means that the entire temporary … Cxf Mitigation only Fix from $1,6002025-07-15 HIGH 7.5 CVE-2025-53506 Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 client did not acknowledge the initial settings frame that reduces the … Tomcat after 11.0.8 Fix from $1,9502025-07-10 HIGH 7.5 CVE-2025-49763 ESI plugin does not have the limit for maximum inclusion depth, and that allows excessive memory consumption if malicious instructions are inserted. … Traffic Server 9.2.11 / 10.0.6+ Fix from $1,9502025-06-19 MEDIUM 6.5 CVE-2025-46392 Uncontrolled Resource Consumption vulnerability in Apache Commons Configuration 1.x. There are a number of issues in Apache Commons Configuration 1.… Commons Configuration 2.0+ Fix from $1,6002025-05-09