CWE-407: CWE-407
Yearly Trend
Top Affected Vendors
All CWE-407 CVEs (26)
This vulnerability in minimatch allows attackers to cause denial of service by crafting glob patterns with multiple non-adjacent ** segments, causing ...
Feb 26, 2026This vulnerability in Django allows remote attackers to cause denial-of-service by sending crafted inputs with many unmatched HTML end tags to specifi...
Feb 3, 2026This vulnerability in Django's ASGIRequest component allows remote attackers to cause denial-of-service by sending crafted requests with multiple dupl...
Feb 3, 2026A denial-of-service vulnerability in Django's XML deserializer allows remote attackers to cause CPU and memory exhaustion via specially crafted XML in...
Dec 2, 2025This vulnerability in HAProxy's mjson library allows remote attackers to cause denial of service through inefficient algorithm complexity when process...
Nov 19, 2025A denial-of-service vulnerability exists in Django's redirect functions due to inefficient NFKC Unicode normalization on Windows. Attackers can crash ...
Nov 5, 2025This vulnerability in GitLab CE/EE causes performance degradation when viewing diffs of merge requests with conflicts, potentially leading to denial o...
Feb 5, 2025This vulnerability in GitLab allows attackers to cause denial of service by making requests for diff files on commits or merge requests. All GitLab CE...
Dec 12, 2024This vulnerability in .NET, .NET Framework, and Visual Studio allows attackers to cause a denial of service by sending specially crafted requests to a...
Oct 8, 2024This vulnerability in .NET and Visual Studio allows attackers to cause a denial of service by sending specially crafted requests that trigger ineffici...
Oct 8, 2024CVE-2023-4408 is a denial-of-service vulnerability in BIND's DNS message parsing code where crafted queries cause excessive CPU consumption due to alg...
Feb 13, 2024PeterO.Cbor versions 4.0.0 through 4.5.0 contain a denial of service vulnerability where specially crafted CBOR data can crash applications using the ...
Jan 3, 2024CVE-2023-38285 is a denial-of-service vulnerability in Trustwave ModSecurity 3.x caused by inefficient algorithmic complexity in four transformation f...
Jul 26, 2023A Denial of Service vulnerability in GitLab CE/EE allows attackers to crash the service by uploading a specially crafted cargo.toml file. This affects...
Nov 26, 2024This CVE describes a Hash Denial of Service (HashDoS) vulnerability in OpenResty's string hashing function. Attackers can send crafted requests to cau...
Jul 23, 2024This vulnerability in Qt's QDom XML processing allows an attacker to cause a denial of service through algorithmic complexity attacks. Applications us...
Mar 21, 2025A denial-of-service vulnerability in GnuTLS allows attackers to cause excessive CPU and memory consumption by presenting malicious certificates with n...
Feb 9, 2026CVE-2025-12084 is a denial-of-service vulnerability in Python's xml.dom.minidom module where building deeply nested XML documents triggers quadratic t...
Dec 3, 2025This vulnerability allows remote attackers to cause a Hash DoS attack by initiating QUIC connections with colliding Source Connection IDs, leading to ...
Mar 31, 2025A hash collision vulnerability in Kwik's connection management hash table allows remote attackers to cause high CPU load through Hash DoS attacks by i...
Feb 20, 2025A hash collision vulnerability in LSQUIC (LiteSpeed QUIC) before version 4.2.0 allows remote attackers to cause high CPU consumption on servers throug...
Feb 20, 2025This vulnerability in GnuTLS (via libtasn1) allows remote attackers to cause denial-of-service by sending specially crafted certificates that trigger ...
Feb 10, 2025This vulnerability allows unauthenticated remote attackers to cause high CPU usage on Cisco Email Security Appliances by sending crafted TLS packets, ...
Nov 18, 2024A denial-of-service vulnerability in GitLab allows attackers to create cyclic references between epics, causing resource exhaustion and service disrup...
Jan 9, 2025Mattermost versions 10.11.0 through 10.11.8 have a CPU exhaustion vulnerability where authenticated users can send posts with thousands of space-separ...
Jan 16, 2026CVE-2025-66382 is a denial-of-service vulnerability in libexpat where a specially crafted XML file (~2MB) can cause excessive processing time (dozens ...
Nov 28, 2025About CWE-407 (CWE-407)
Our database tracks 26 CVEs classified as CWE-407, with 0 rated critical and 13 rated high severity. The average CVSS score for CWE-407 vulnerabilities is 6.3.
External reference: View CWE-407 on MITRE CWE →
Monitor CWE-407 Vulnerabilities
Get alerted when new CWE-407 CVEs affect your infrastructure.
Start Monitoring Free