CWE-400: Resource Exhaustion

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, leading to exhaustion.

696
Total CVEs
21
Critical
456
High
7.0
Avg CVSS

Yearly Trend

2026
73
2025
268
2024
171
2023
96
2022
32

Top Affected Vendors

1 Oracle 50
2 Microsoft 49
3 Apple 25
4 Fedoraproject 19
5 Linux 18
6 Google 17
7 Debian 16
8 Netapp 13
9 Apache 12
10 Juniper 11

All Resource Exhaustion CVEs (696)

CVE-2025-30753
6.5

This vulnerability in Oracle WebLogic Server allows authenticated attackers with low privileges to cause a denial of service (DoS) by crashing or hang...

Jul 15, 2025
CVE-2025-6712
6.5

MongoDB Server versions 8.0 prior to 8.0.10 have a memory management vulnerability where certain internal operations can cause excessive memory consum...

Jul 7, 2025
CVE-2025-44559
6.5

A vulnerability in Realtek RTL8762E BLE SDK v1.4.0 allows attackers within Bluetooth range to cause a Denial of Service (DoS) by sending specially cra...

Jun 27, 2025
CVE-2025-3112
6.5

This vulnerability allows an authenticated attacker to cause a denial of service by sending manipulated HTTPS Content-Length headers to the webserver,...

Jun 10, 2025
CVE-2025-22892
6.5

This vulnerability allows unauthenticated attackers on adjacent networks to cause denial of service by exhausting resources in OpenVINO model server s...

May 13, 2025
CVE-2025-43857
6.5

This vulnerability in Ruby's Net::IMAP library allows a malicious or compromised IMAP server to cause denial of service through memory exhaustion. Whe...

Apr 28, 2025
CVE-2025-21577
6.5

This vulnerability in MySQL Server's InnoDB component allows authenticated attackers with low privileges to cause a denial of service (DoS) by crashin...

Apr 15, 2025
CVE-2025-21575
6.5

A vulnerability in MySQL Server's parser component allows low-privileged attackers with network access to cause denial of service by crashing or hangi...

Apr 15, 2025
CVE-2025-29490
6.5

A segmentation fault vulnerability in libming v0.4.8's decompileCALLMETHOD function allows attackers to cause Denial of Service (DoS) by processing a ...

Mar 27, 2025
CVE-2025-2820
6.5

An authenticated attacker can cause a denial-of-service condition on affected Bizerba devices via network access, disrupting normal operations. This a...

Mar 26, 2025
CVE-2025-0191
6.5

A Denial of Service vulnerability in gaizhenbiao/chuanhuchatgpt allows attackers to crash the service by uploading files with excessively long filenam...

Mar 20, 2025
CVE-2024-7771
6.5

A denial-of-service vulnerability in Dockerized anything-llm allows attackers to crash the entire site instance by uploading an audio file with a very...

Mar 20, 2025
CVE-2024-12074
6.5

This CVE describes a Denial of Service vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 where attackers can crash the server by up...

Mar 20, 2025
CVE-2024-11033
6.5

A Denial of Service vulnerability in binary-husky/gpt_academic version 3.83 allows attackers to crash the server by uploading files with excessively l...

Mar 20, 2025
CVE-2025-27100
6.5

An authenticated denial-of-service vulnerability in lakeFS allows authenticated users to crash the server by exhausting memory. This affects lakeFS ve...

Feb 21, 2025
CVE-2025-21352
6.5

This vulnerability in Internet Connection Sharing (ICS) allows attackers to cause a denial of service condition by sending specially crafted network p...

Feb 11, 2025
CVE-2025-25186
6.5

This vulnerability in Ruby's Net::IMAP library allows a malicious IMAP server to cause denial of service through memory exhaustion. When a client conn...

Feb 10, 2025
CVE-2024-45626
6.5

Apache James server versions below 3.7.6 and 3.8.2 have a vulnerability in their JMAP HTML-to-text conversion implementation that allows attackers to ...

Feb 6, 2025
CVE-2024-57082
6.5

A prototype pollution vulnerability in the lib.createUploader function of @rpldy/uploader v1.8.1 allows attackers to supply crafted payloads that can ...

Feb 5, 2025
CVE-2024-43763
6.5

This CVE describes a logic error in Android's Bluetooth GATT server component that allows nearby attackers to cause denial of service without user int...

Jan 21, 2025
CVE-2024-47239
6.5

Dell PowerScale OneFS versions 8.2.2.x through 9.9.0.0 contain an uncontrolled resource consumption vulnerability that allows remote low-privileged at...

Jan 8, 2025
CVE-2024-12698
6.5

This vulnerability is an incomplete fix for the Rapid Reset attack (CVE-2023-39325/CVE-2023-44487) in the ose-olm-catalogd-container component. It all...

Dec 18, 2024
CVE-2024-21230
6.5

This vulnerability in MySQL Server's optimizer component allows authenticated attackers with low privileges to cause denial of service by crashing or ...

Oct 15, 2024
CVE-2024-42849
6.5

A vulnerability in Silverpeas versions 6.4.2 and earlier allows remote attackers to cause denial of service through the password change function. This...

Aug 16, 2024
CVE-2024-5423
6.5

This vulnerability allows attackers to cause Denial of Service (DoS) conditions in GitLab instances by exploiting resource exhaustion through the banz...

Aug 8, 2024
CVE-2024-4210
6.5

This vulnerability allows attackers to cause a Denial of Service (DoS) condition in GitLab by uploading specially crafted adoc (AsciiDoc) files. All G...

Aug 8, 2024
CVE-2024-3297
6.5

A denial-of-service vulnerability in the Matter protocol's CASE protocol allows attackers to replay manipulated CASE Sigma1 messages, causing affected...

Jul 24, 2024
CVE-2024-21177
6.5

This vulnerability in MySQL Server's Optimizer component allows authenticated attackers with network access to cause a denial of service by crashing o...

Jul 16, 2024
CVE-2024-21171
6.5

This vulnerability in MySQL Server's Optimizer component allows low-privileged attackers with network access to cause a denial of service (DoS) by cra...

Jul 16, 2024
CVE-2023-39329
6.5

This vulnerability in OpenJPEG allows an attacker to cause a denial of service through resource exhaustion by providing a specially crafted image file...

Jul 13, 2024
CVE-2024-39557
6.5

An unauthenticated adjacent attacker can exploit a memory leak in Juniper's Layer 2 Address Learning Daemon (l2ald) on Junos OS Evolved to cause syste...

Jul 10, 2024
CVE-2024-4557
6.5

This vulnerability allows attackers to cause Denial of Service (DoS) conditions in GitLab instances by exploiting resource exhaustion in the banzai pi...

Jun 27, 2024
CVE-2024-27812
6.5

A denial-of-service vulnerability in visionOS file handling protocol allows attackers to crash devices by processing malicious web content. This affec...

Jun 10, 2024
CVE-2024-27800
6.5

This vulnerability in Apple operating systems allows processing a maliciously crafted message to cause a denial-of-service condition. It affects multi...

Jun 10, 2024
CVE-2024-22588
6.5

Kwik commit 745fd4e2 fails to discard unused encryption keys as required by RFC 9001, potentially allowing attackers to decrypt previously encrypted Q...

May 24, 2024
CVE-2024-30019
6.5

This vulnerability in the Windows DHCP Server service allows an attacker to send specially crafted packets to cause a denial of service. Systems runni...

May 14, 2024
CVE-2024-32476
6.5

This CVE describes a denial-of-service vulnerability in Argo CD where specially crafted ignoreDifferences configurations can cause excessive memory co...

May 14, 2024
CVE-2023-0056
6.5

An uncontrolled resource consumption vulnerability in HAProxy could allow an authenticated remote attacker to crash the service by running a specially...

Mar 23, 2023
CVE-2024-13065
6.3

This vulnerability in Akinsoft MyRezzta allows attackers to manipulate input data to cause uncontrolled resource consumption (flooding), potentially l...

Sep 3, 2025
CVE-2026-26066
6.2

ImageMagick versions before 7.1.2-15 and 6.9.13-40 contain a vulnerability where specially crafted IPTC profile data can trigger an infinite loop when...

Feb 24, 2026
CVE-2025-66676
6.2

A vulnerability in IObit Unlocker v1.3.0.11 allows attackers to cause a Denial of Service (DoS) by sending specially crafted requests. This affects us...

Feb 13, 2026
CVE-2024-40664
6.2

This vulnerability in Android's accessibility services allows an attacker to hide enabled accessibility services through a logic error in Accessibilit...

Sep 4, 2025
CVE-2025-26423
6.2

This vulnerability in Android's Wi-Fi configuration validation allows local attackers to trigger a permanent denial-of-service condition without user ...

Sep 4, 2025
CVE-2025-29957
6.2

This vulnerability in Windows Deployment Services allows an unauthorized attacker to cause a denial of service through uncontrolled resource consumpti...

May 13, 2025
CVE-2025-0426
6.2

This vulnerability in Kubernetes allows unauthenticated attackers to cause Node Denial of Service by sending numerous container checkpoint requests to...

Feb 13, 2025
CVE-2021-47329
6.2

This CVE describes a resource leak vulnerability in the Linux kernel's megaraid_sas driver. When the driver fails during PCI device probe, it doesn't ...

May 21, 2024
CVE-2025-37139
6.0

This vulnerability in AOS firmware allows authenticated attackers to delete critical boot information, permanently bricking the system and requiring h...

Oct 14, 2025
CVE-2024-8184
5.9

This vulnerability in Jetty's ThreadLimitHandler.getRemote() allows unauthenticated attackers to send crafted requests that trigger OutOfMemory errors...

Oct 14, 2024
CVE-2024-20500
5.8

This vulnerability allows unauthenticated remote attackers to cause a denial-of-service condition in the Cisco AnyConnect VPN server on Meraki MX and ...

Oct 2, 2024
CVE-2025-46304
5.7

This vulnerability allows a malicious HID (Human Interface Device) like a keyboard or mouse to cause unexpected process crashes on affected Apple devi...

Feb 11, 2026

About Resource Exhaustion (CWE-400)

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, leading to exhaustion.

Our database tracks 696 CVEs classified as CWE-400, with 21 rated critical and 456 rated high severity. The average CVSS score for Resource Exhaustion vulnerabilities is 7.0.

External reference: View CWE-400 on MITRE CWE →

Monitor Resource Exhaustion Vulnerabilities

Get alerted when new Resource Exhaustion CVEs affect your infrastructure.

Start Monitoring Free