CWE-400: Resource Exhaustion

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, leading to exhaustion.

695
Total CVEs
21
Critical
455
High
7.0
Avg CVSS

Yearly Trend

2026
73
2025
268
2024
171
2023
96
2022
32

Top Affected Vendors

1 Oracle 50
2 Microsoft 49
3 Apple 25
4 Fedoraproject 19
5 Linux 18
6 Google 17
7 Debian 16
8 Netapp 13
9 Apache 12
10 Juniper 11

All Resource Exhaustion CVEs (695)

CVE-2021-0230
7.5

This vulnerability causes a slow kernel memory leak on Juniper SRX Series devices with link aggregation configured when AE interface statistics are fe...

Apr 22, 2021
CVE-2021-28165
7.5

This vulnerability in Eclipse Jetty allows denial-of-service attacks by causing 100% CPU usage when processing large invalid TLS frames. Attackers can...

Apr 1, 2021
CVE-2019-19343
7.5

CVE-2019-19343 is a memory leak vulnerability in Undertow's HttpOpenListener when using Remoting in Red Hat JBoss EAP. This flaw allows attackers to c...

Mar 23, 2021
CVE-2021-21341
7.5

CVE-2021-21341 is a denial-of-service vulnerability in XStream library where specially crafted XML input can cause 100% CPU consumption on target syst...

Mar 23, 2021
CVE-2021-22883
7.5

Node.js servers are vulnerable to denial of service attacks when attackers establish numerous connections with unknown protocols, causing file descrip...

Mar 3, 2021
CVE-2021-22882
7.5

This vulnerability allows attackers to spoof camera devices and send malicious data to UniFi Protect controllers, causing denial-of-service crashes. I...

Feb 23, 2021
CVE-2021-27405
7.5

A ReDoS (Regular Expression Denial of Service) vulnerability exists in the @progfay/scrapbox-parser package for Node.js, allowing attackers to cause d...

Feb 19, 2021
CVE-2020-13949
7.5

This vulnerability in Apache Thrift allows malicious RPC clients to send specially crafted short messages that trigger excessive memory allocation, po...

Feb 12, 2021
CVE-2021-22985
7.5

This vulnerability allows authenticated VPN users on BIG-IP APM to cause excessive memory consumption in the Traffic Management Microkernel (TMM), pot...

Feb 12, 2021
CVE-2020-5023
7.5

IBM Spectrum Protect Plus versions 10.1.0 through 10.1.7 contain a vulnerability that allows remote attackers to inject arbitrary data, causing resour...

Feb 10, 2021
CVE-2021-21240
7.5

This vulnerability in httplib2 allows a malicious server to cause denial of service by sending long sequences of non-breaking space characters in WWW-...

Feb 8, 2021
CVE-2021-21294
7.5

CVE-2021-21294 is a denial-of-service vulnerability in http4s-blaze-server where the underlying blaze-core library accepts connections without bounds,...

Feb 2, 2021
CVE-2020-27295
7.5

CVE-2020-27295 is a denial-of-service vulnerability in the OPC UA Tunneller software where uncontrolled resource consumption allows attackers to crash...

Jan 26, 2021
CVE-2020-8295
7.5

A logic flaw in Nextcloud Server's password reset functionality allows attackers to trigger a denial of service condition. This affects Nextcloud Serv...

Jan 26, 2021
CVE-2020-4766
7.5

This vulnerability in IBM MQ Internet Pass-Thru allows remote attackers to cause a denial of service by sending specially crafted MQ data requests tha...

Jan 22, 2021
CVE-2021-0202
7.5

This vulnerability causes a memory leak in Juniper Networks MX Series and EX9200 Series platforms with Trio-based MPC when specific IRB and VPLS/bridg...

Jan 15, 2021
CVE-2020-29490
7.5

This vulnerability allows a remote authenticated attacker to cause a Denial of Service (Storage Processor Panic) on Dell EMC Unity storage systems by ...

Jan 5, 2021
CVE-2020-5423
7.5

CVE-2020-5423 is a denial-of-service vulnerability in Cloud Foundry's CAPI (Cloud Controller) where unauthenticated attackers can send malicious YAML ...

Dec 2, 2020
CVE-2025-20340
7.4

This vulnerability allows an unauthenticated attacker on the same network segment to send excessive ARP traffic to the management interface of Cisco I...

Sep 10, 2025
CVE-2022-29167
7.4

CVE-2022-29167 is a regular expression denial-of-service (ReDoS) vulnerability in the Hawk HTTP authentication library. Attackers can craft malicious ...

May 5, 2022
CVE-2021-32723
7.4

CVE-2021-32723 is a Regular Expression Denial of Service (ReDoS) vulnerability in Prism syntax highlighting library versions before 1.24.0. Attackers ...

Jun 28, 2021
CVE-2025-27829
7.3

A vulnerability in Stormshield Network Security (SNS) firewalls allows attackers to disrupt multicast traffic when multicast streams are enabled on mu...

Apr 1, 2025
CVE-2025-24126
7.3

This CVE describes an input validation vulnerability in multiple Apple operating systems that could allow an attacker on the local network to cause sy...

Jan 27, 2025
CVE-2021-47371
7.1

A memory leak vulnerability in the Linux kernel's nexthop notification chain allows unregistered listeners to retain references to nexthop objects, ca...

May 21, 2024
CVE-2023-34458
7.1

A vulnerability in mx-chain-go's transaction processing incorrectly increments the sender's nonce when a relayed inner transaction fails, allowing an ...

Jul 13, 2023
CVE-2024-26976
7.0

This vulnerability in the Linux kernel's KVM subsystem could allow an attacker to cause a denial-of-service (DoS) condition or potentially execute arb...

May 1, 2024
CVE-2025-41226
6.8

This CVE describes a denial-of-service vulnerability in VMware ESXi where an authenticated attacker with guest operation privileges can crash guest VM...

May 20, 2025
CVE-2024-57782
6.8

A denial-of-service vulnerability in Docker-proxy v18.09.0 allows attackers to crash or degrade the proxy service, disrupting container networking. Th...

Feb 13, 2025
CVE-2026-26047
6.5

This vulnerability allows authenticated Moodle users to craft malicious TeX formulas that consume excessive server resources when rendered, potentiall...

Feb 21, 2026
CVE-2025-62854
6.5

An uncontrolled resource consumption vulnerability in QNAP File Station 5 allows authenticated remote attackers to cause denial-of-service conditions....

Feb 11, 2026
CVE-2026-25579
6.5

This vulnerability allows authenticated users to crash Navidrome servers by sending requests with excessively large size parameters to image endpoints...

Feb 4, 2026
CVE-2026-24738
6.5

The gmrtd Go library for reading Machine Readable Travel Documents (MRTDs) has a vulnerability where ReadFile accepts TLV structures with lengths up t...

Jan 27, 2026
CVE-2026-21696
6.5

This vulnerability allows low-privileged users to trigger a database flood in Pterodactyl Panel by exploiting Wings' failure to respect SQLite's param...

Jan 19, 2026
CVE-2025-69199
6.5

This vulnerability allows attackers to perform denial-of-service attacks against Pterodactyl Wings servers by exploiting missing rate limiting and mes...

Jan 19, 2026
CVE-2025-69198
6.5

This CVE describes a race condition vulnerability in Pterodactyl Panel where concurrent requests can bypass resource limits. Malicious users can creat...

Jan 19, 2026
CVE-2025-67835
6.5

This vulnerability allows authenticated attackers to cause a Denial-of-Service (DoS) condition in Paessler PRTG Network Monitor by exploiting the Noti...

Jan 14, 2026
CVE-2025-60458
6.5

UxPlay 1.72 contains a double free vulnerability in RTSP request handling. Attackers can send specially crafted RTSP TEARDOWN requests to trigger mult...

Dec 29, 2025
CVE-2025-8872
6.5

This vulnerability allows attackers to send specially crafted OSPFv3 packets to Arista EOS devices, causing high CPU utilization that can restart the ...

Dec 16, 2025
CVE-2025-48631
6.5

This vulnerability in Android's LocalImageResolver component allows remote attackers to cause persistent denial of service through resource exhaustion...

Dec 8, 2025
CVE-2025-55128
6.5

An uncontrolled resource consumption vulnerability in userlog-index.php allows authenticated admin users to request arbitrarily large page sizes, pote...

Nov 20, 2025
CVE-2025-11681
6.5

An authenticated user can cause a denial-of-service by crashing the MFserver process in vulnerable M-Files Server versions. This affects organizations...

Nov 17, 2025
CVE-2025-62706
6.5

CVE-2025-62706 is a denial-of-service vulnerability in Authlib's JWE implementation where DEFLATE decompression lacks size limits. Attackers can send ...

Oct 22, 2025
CVE-2025-53068
6.5

A local privilege escalation vulnerability in Oracle Solaris 11 kernel allows authenticated low-privileged users to cause a complete denial-of-service...

Oct 21, 2025
CVE-2025-37148
6.5

An unauthenticated remote attacker can send specially crafted ethernet frames to vulnerable ArubaOS devices, causing denial of service that requires m...

Oct 14, 2025
CVE-2025-52961
6.5

An unauthenticated adjacent attacker can cause denial-of-service on affected Juniper PTX devices by sending specific valid CFM traffic that spikes CPU...

Oct 9, 2025
CVE-2025-52867
6.5

An uncontrolled resource consumption vulnerability in Qsync Central allows authenticated remote attackers to cause denial-of-service conditions. This ...

Oct 3, 2025
CVE-2025-29898
6.5

An uncontrolled resource consumption vulnerability in Qsync Central allows authenticated remote attackers to cause denial-of-service conditions. This ...

Aug 29, 2025
CVE-2025-55521
6.5

An authenticated attacker can send a specially crafted POST request to the /settings/localisation endpoint in Akaunting v3.1.18, causing a Denial of S...

Aug 21, 2025
CVE-2025-50082
6.5

This vulnerability in MySQL Server's optimizer component allows authenticated attackers with low privileges to cause denial of service by crashing or ...

Jul 15, 2025
CVE-2025-30753
6.5

This vulnerability in Oracle WebLogic Server allows authenticated attackers with low privileges to cause a denial of service (DoS) by crashing or hang...

Jul 15, 2025

About Resource Exhaustion (CWE-400)

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, leading to exhaustion.

Our database tracks 695 CVEs classified as CWE-400, with 21 rated critical and 455 rated high severity. The average CVSS score for Resource Exhaustion vulnerabilities is 7.0.

External reference: View CWE-400 on MITRE CWE →

Monitor Resource Exhaustion Vulnerabilities

Get alerted when new Resource Exhaustion CVEs affect your infrastructure.

Start Monitoring Free