Security Risk Category

Denial of Service Security Risks — Page 4

Published vulnerability pages connected to Denial of Service. Each page keeps one canonical URL and focused remediation guidance.

215 published Denial of Service risks

Denial of Service risks

Showing 109–144 of 215 published risks.

highEPSS 0.007

CVE-2026-45305 in Symfony YAML

Symfony YAML can hang on crafted YAML because of slow regex backtracking.

CVE-2026-45305phpweb-applicationinput-validationdenial-of-service

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-6683 in FatFs

FatFs R0.16 and earlier contains a divide-by-zero in exFAT sync logic bug when crafted metadata causes n_fatent - 2 to be zero during write/sync operations. This maps to CWE-369 (Divide By Zero). Estimated CVSS v3.1 vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H (4.6, Medium). Network-delivered update media can make this remote in some pipelines. The estimated CISA SSVC vectors are Exploitation: PoC, Technical Impact: Partial.

CVE-2026-6683supply-chaindenial-of-service

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-6684 in FatFs

FatFs prior to R0.16 that use GPT scanning with 'FF_LBA64 = 1' contains an issue where an unbounded loop count derived from GPT header field GPTH_PtNum, enabling extremely long or effectively infinite mount-time scans. This maps to CWE-835 (Loop with Unreachable Exit Condition). Estimated CVSS v3.1 vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H (4.6, Medium). The estimated CISA SSVC vectors are Exploitation: PoC, Technical Impact: Partial.

CVE-2026-6684supply-chaindenial-of-service

Updated Jul 15, 2026

highEPSS 0.008

CVE-2026-24264 in NVIDIA Triton Inference Server

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause improper handling of highly compressed data. A successful exploit of this vulnerability might lead to denial of service.

CVE-2026-24264linuxdevopsinput-validationdenial-of-service

Updated Jul 15, 2026

mediumEPSS 0.007

CVE-2026-24266 in NVIDIA Triton Inference Server

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a use-after-free issue. A successful exploit of this vulnerability might lead to denial of service.

CVE-2026-24266linuxdevopsdenial-of-servicememory-corruption

Updated Jul 15, 2026

high

CVE-2026-20213 in ClamAV

A vulnerability in the PE file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in PE files during scanning, which may result in an out-of-bounds buffer write. An attacker could exploit this vulnerability by submitting a crafted file that contains PE content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.

CVE-2026-20213network-securitydenial-of-servicememory-corruption

Updated Jul 15, 2026

high

CVE-2026-20214 in ClamAV

A vulnerability in the FSG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in FSG files during scanning, which may result in an out-of-bounds buffer write. An attacker could exploit this vulnerability by submitting a crafted file that contains portable executable content compressed with FSG to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.

CVE-2026-20214network-securitydenial-of-servicememory-corruption

Updated Jul 15, 2026

high

CVE-2026-20215 in ClamAV

A vulnerability in the 7z file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in 7z files during scanning, which may result in an out-of-bounds buffer write. An attacker could exploit this vulnerability by submitting a crafted file that contains 7z content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.

CVE-2026-20215network-securitydenial-of-servicememory-corruption

Updated Jul 15, 2026

high

CVE-2026-20216 in ClamAV

A vulnerability in the InstallShield file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper handling of temporary resources during file scanning. An attacker could exploit this vulnerability by submitting a crafted InstallShield file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to terminate the ClamAV scanning process and temporarily consume available system resources, resulting in a DoS condition on the affected software.

CVE-2026-20216network-securityinput-validationdenial-of-service

Updated Jul 15, 2026

high

CVE-2026-20217 in ClamAV

A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in PESpin files during scanning, which may result in an out-of-bounds buffer write. An attacker could exploit this vulnerability by submitting a crafted file that contains PESpin content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.

CVE-2026-20217network-securitydenial-of-servicememory-corruption

Updated Jul 15, 2026

high

CVE-2026-20243 in ClamAV

A vulnerability in the ALZ file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in ALZ files during scanning, which may result in an out-of-bounds buffer write. An attacker could exploit this vulnerability by submitting a crafted file that contains ALZ content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.

CVE-2026-20243network-securitydenial-of-servicememory-corruption

Updated Jul 15, 2026

high

CVE-2026-20244 in ClamAV

A vulnerability in the DMG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in DMG files during scanning, which may result in an integer overflow on 32-bit platforms only. An attacker could exploit this vulnerability by submitting a crafted file that contains DMG content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.

CVE-2026-20244network-securitydenial-of-servicememory-corruption

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-49087 in Kibana

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted bulk deletion request that causes excessive resource consumption, which may render Kibana unavailable.

CVE-2026-49087devopsweb-applicationdenial-of-service

Updated Jul 15, 2026

highEPSS 0.006

CVE-2026-54399 in Apache HttpComponents Core

Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending messages with excessive number of headers / excessive header length

CVE-2026-54399javanetwork-securitydenial-of-service

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-56148 in Elasticsearch

Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted query that causes excessive resource consumption while the request is processed, which may render the affected node unavailable.

CVE-2026-56148api-securitydevopsdenial-of-service

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-56149 in Elasticsearch

Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). A user with elevated privileges can submit a specially crafted machine learning request that causes excessive memory consumption, which may render the affected node unavailable.

CVE-2026-56149api-securitydevopsdenial-of-service

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-56150 in Elastic Fleet Server

Allocation of Resources Without Limits or Throttling (CWE-770) in Fleet Server can lead to a denial of service via Excessive Allocation (CAPEC-130). An attacker can submit a specially crafted request to an upload endpoint that causes excessive memory consumption, which may render Fleet Server unavailable.

CVE-2026-56150api-securitydevopsdenial-of-service

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-56151 in Kibana

Improper Input Validation (CWE-20) in Kibana can lead to a denial of service via Input Data Manipulation (CAPEC-153). An authenticated user can submit a specially crafted Fleet policy input that is not correctly validated, which can render Fleet agent, server, and policy management functionality unavailable.

CVE-2026-56151devopsweb-applicationinput-validationdenial-of-service

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-10085 in Mattermost Server

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict the group_constrained channel flag to public and private channels that support group synchronization, which allows an ordinary group or direct message member to remove all participants from the conversation via the channel patch API.. Mattermost Advisory ID: MMSA-2026-00688

CVE-2026-10085api-securityweb-applicationauthorization-bypassdenial-of-service

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-6850 in Mattermost Server

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate the length and content of message attachment field values, which allows an authenticated attacker to cause a denial of service for all users in a channel via a post containing a specially crafted payload that triggers catastrophic backtracking in the client-side markdown parser.. Mattermost Advisory ID: MMSA-2026-00658

CVE-2026-6850api-securityweb-applicationinput-validationdenial-of-service

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-40467 in GNU awk

Use After Free vulnerability has been found in "io.c" program file of gawk (do_getline_redir() routine). This issue may lead to a crash. It affects gawk in versions 5.4.0 and below.

CVE-2026-40467linuxdenial-of-servicememory-corruption

Updated Jul 15, 2026

lowEPSS 0.002

CVE-2026-40468 in GNU awk

Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions 5.4.0 and below.

CVE-2026-40468linuxinput-validationdenial-of-servicememory-corruption

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-40469 in GNU awk

Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). This issue could be used to overwrite gawk heap metadata and objects causing the program to crash. It affects 32-bit builds of gawk in versions 5.4.0 and below.

CVE-2026-40469linuxinput-validationdenial-of-servicememory-corruption

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-40553 in GNU awk

Buffer overflow vulnerability has been found in "extension/readdir.c" program file of gawk (ftype() routine). This issue could be used to crash the program and potentially to achieve code execution, although the latter has not been confirmed to be feasible. It affects gawk in versions 5.4.0 and below.

CVE-2026-40553linuxdenial-of-servicememory-corruption

Updated Jul 15, 2026

criticalEPSS 0.002

CVE-2026-57433 in Storable for Perl

Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record. retrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value. A crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization.

CVE-2026-57433input-validationdenial-of-servicememory-corruptionunsafe-deserialization

Updated Jul 15, 2026

mediumEPSS 0.001

CVE-2026-15681 in AnyDesk

AnyDesk Screen Recording Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service condition on affected installations of AnyDesk. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of screen recording files. By creating a junction, an attacker can abuse the service to create arbitrary files. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-26591.

CVE-2026-15681denial-of-servicepath-traversalfile-write

Updated Jul 15, 2026

mediumEPSS 0.001

CVE-2026-15682 in AnyDesk

AnyDesk Support Information Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service condition on affected installations of AnyDesk. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Send Support Information feature. By creating a junction, an attacker can abuse the service to create arbitrary files. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-26645.

CVE-2026-15682denial-of-servicepath-traversalfile-write

Updated Jul 15, 2026

highEPSS 0.004

CVE-2026-15685 in Ollama

Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Ollama. Authentication is not required to exploit this vulnerability. The specific flaw exists within the downloadBlob function. The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of an allocated array. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-27277.

CVE-2026-15685input-validationdenial-of-servicememory-corruption

Updated Jul 15, 2026

highEPSS 0.003

CVE-2024-7708 in Eclipse Jetty

For requests that have a body, but reading the body may end up in reading 0 bytes, there is a buffer leak. This is particularly the case for 100-Continue, but any request where the network is slow can leak.

CVE-2024-7708javaweb-applicationdenial-of-service

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-13699 in Eclipse KUKSA Databroker

In Eclipse KUKSA Databroker version 0.6.1, the kuksa.val.v2.VAL/PublishValue gRPC handler fails to validate the existence of the optional data_point field in PublishValueRequest. When a request contains a valid signal_id but omits data_point, the server directly calls unwrap() on request.data_point, triggering a panic in the Tokio worker thread. This issue can be triggered by any client holding a valid JWT token. Unauthenticated or invalid-token requests are rejected and do not reach the vulnerable path. The panic causes the individual gRPC call to be cancelled but does not terminate the Databroker process, which remains available for subsequent requests.

CVE-2026-13699api-securityindustrial-controlinput-validationdenial-of-service

Updated Jul 15, 2026

criticalEPSS 0.003

CVE-2026-58319 in Apache Doris

Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated attacker with network access to the FE HTTP service could perform unauthorized administrative operations, potentially affecting cluster integrity and availability and leading to cluster instability or denial of service. This issue affects Apache Doris versions prior to 3.1.0. Users are advised to upgrade to Apache Doris 3.1.0 or later.

CVE-2026-58319javaweb-applicationauthentication-bypassdenial-of-service

Updated Jul 15, 2026

medium

CVE-2026-59203 in Pillow

Pillow is a Python imaging library. From 12.0.0 through 12.2.0, Pillow's EPS parser in PIL/EpsImagePlugin.py accepts a negative byte count in the %%BeginBinary directive, allowing a crafted EPS file to cause Image.open() to seek backwards to the same directive and parse it repeatedly in an infinite loop. This issue is fixed in version 12.3.0.

CVE-2026-59203pythoninput-validationdenial-of-service

Updated Jul 15, 2026

high

CVE-2026-59204 in Pillow

Pillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component_width across every tile in a JPEG2000 image instead of recomputing it per tile, allowing a crafted tiled JPEG2000 file to force substantially higher transient memory usage and trigger out-of-memory failures during decoding. This issue is fixed in version 12.3.0.

CVE-2026-59204pythoninput-validationdenial-of-service

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-49090 in Elasticsearch

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted bulk request that causes sustained high CPU consumption, which can render the affected node unable to process requests.

CVE-2026-49090cloud-securitydenial-of-service

Updated Jul 15, 2026

highEPSS 0.006

CVE-2026-54428 in Apache HttpComponents Core

Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending oversized compressed header blocks before the HTTP/2 SETTINGS acknowledgement causes the configured header list size limit to be applied.

CVE-2026-54428javanetwork-securitydenial-of-service

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-47262 in containerd

containerd is an open-source container runtime. Versions prior to 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2, contain a vulnerability that allows a maliciously crafted image to cause a Denial of Service (DoS) condition. When creating a container from this image, memory exhaustion occurs, leading to an Out Of Memory (OOM) kill of the containerd process. This renders the container runtime API unavailable and can disrupt clients such as the Docker Engine or Kubernetes control-plane components. This issue has been fixed in versions 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2.

CVE-2026-47262api-securitycloud-securitydevopsdenial-of-service

Updated Jul 15, 2026