CWE-400: Resource Exhaustion

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, leading to exhaustion.

699
Total CVEs
21
Critical
459
High
7.0
Avg CVSS

Yearly Trend

2026
73
2025
268
2024
171
2023
96
2022
32

Top Affected Vendors

1 Oracle 50
2 Microsoft 49
3 Apple 25
4 Fedoraproject 19
5 Linux 18
6 Google 17
7 Debian 16
8 Netapp 13
9 Apache 12
10 Juniper 11

All Resource Exhaustion CVEs (699)

CVE-2024-8184
5.9

This vulnerability in Jetty's ThreadLimitHandler.getRemote() allows unauthenticated attackers to send crafted requests that trigger OutOfMemory errors...

Oct 14, 2024
CVE-2024-20500
5.8

This vulnerability allows unauthenticated remote attackers to cause a denial-of-service condition in the Cisco AnyConnect VPN server on Meraki MX and ...

Oct 2, 2024
CVE-2025-46304
5.7

This vulnerability allows a malicious HID (Human Interface Device) like a keyboard or mouse to cause unexpected process crashes on affected Apple devi...

Feb 11, 2026
CVE-2025-7105
5.7

This vulnerability in LibreChat allows attackers to exploit an unrestricted fork function to create numerous content forks containing large Mermaid gr...

Feb 2, 2026
CVE-2025-26472
5.7

This vulnerability in Intel Tiber Edge Platform's Edge Orchestrator software allows authenticated users on adjacent networks to cause denial of servic...

Aug 12, 2025
CVE-2024-57708
5.7

This CVE describes a potential prototype pollution vulnerability in OneTrust SDK version 6.33.0 that could allow a local attacker to cause denial of s...

Jun 25, 2025
CVE-2025-6365
5.7

This vulnerability in HobbesOSR Kitten's set_pte_at function allows attackers to cause resource consumption (denial of service) by manipulating page t...

Jun 20, 2025
CVE-2024-52520
5.7

This vulnerability in Nextcloud Server allows attackers to trick the link reference provider into downloading larger websites than intended when proce...

Nov 15, 2024
CVE-2024-37904
5.7

Minder's Git provider is vulnerable to a denial-of-service attack where authenticated users can cause the Minder server to crash by instructing it to ...

Jun 18, 2024
CVE-2026-20602
5.5

A cache handling vulnerability in macOS allows applications to cause denial-of-service conditions. This affects macOS Sequoia, Tahoe, and Sonoma opera...

Feb 11, 2026
CVE-2025-54150
5.5

An uncontrolled resource consumption vulnerability in Qsync Central allows local attackers with user accounts to launch denial-of-service attacks by e...

Feb 11, 2026
CVE-2025-54151
5.5

An uncontrolled resource consumption vulnerability in Qsync Central allows local attackers with user accounts to launch denial-of-service attacks by e...

Feb 11, 2026
CVE-2025-70347
5.5

A vulnerability in mquickjs allows local attackers to cause denial of service by providing a specially crafted file to the get_mblock_size function. T...

Feb 10, 2026
CVE-2026-25122
5.5

This vulnerability in apko allows attackers to cause resource exhaustion by forcing excessive CPU usage during gzip inflation of malicious APK archive...

Feb 4, 2026
CVE-2025-59529
5.5

Avahi's simple protocol server ignores the documented client connection limit, allowing unprivileged local users to establish unlimited connections. T...

Dec 18, 2025
CVE-2025-48590
5.5

This vulnerability allows a malicious Android app to cause resource exhaustion in the AppOpsService, potentially preventing emergency calls in limited...

Dec 8, 2025
CVE-2025-48576
5.5

This vulnerability in Android's NotificationManagerService allows local attackers to cause permanent denial of service through resource exhaustion. It...

Dec 8, 2025
CVE-2025-48584
5.5

This vulnerability allows attackers to bypass per-package notification channel limits in Android's NotificationManagerService, potentially causing res...

Dec 8, 2025
CVE-2025-13837
5.5

CVE-2025-13837 is a denial-of-service vulnerability in Python's plistlib module where malicious plist files can trigger excessive memory allocation, c...

Dec 1, 2025
CVE-2025-27249
5.5

This vulnerability allows an authenticated local attacker to cause denial of service through uncontrolled resource consumption in Gaudi software. It a...

Nov 11, 2025
CVE-2025-60753
5.5

A vulnerability in libarchive's bsdtar allows attackers to cause denial of service through unbounded memory allocation when processing malicious subst...

Nov 5, 2025
CVE-2025-6075
5.5

This CVE describes a denial-of-service vulnerability in Python's os.path.expandvars() function. When user-controlled input is passed to this function,...

Oct 31, 2025
CVE-2025-61155
5.5

CVE-2025-61155 is an access control vulnerability in GameDriverX64.sys anti-cheat driver that allows user-mode processes to send specially crafted IOC...

Oct 28, 2025
CVE-2025-53053
5.5

This vulnerability in MySQL Server's DML component allows authenticated high-privilege attackers to cause denial of service (server hang/crash) or mod...

Oct 21, 2025
CVE-2025-53054
5.5

A vulnerability in MySQL Server's InnoDB component allows high-privileged attackers with network access to cause denial of service (server hangs or cr...

Oct 21, 2025
CVE-2025-43295
5.5

This CVE describes a denial-of-service vulnerability in Apple operating systems where an application could cause system instability or crashes. It aff...

Sep 15, 2025
CVE-2025-26463
5.5

This Android vulnerability allows resource exhaustion through repeated package access requests, potentially causing persistent denial of service on af...

Sep 4, 2025
CVE-2025-26449
5.5

This CVE describes a resource exhaustion vulnerability in Android's framework that could allow local attackers to cause permanent denial of service wi...

Sep 4, 2025
CVE-2024-49740
5.5

This CVE describes a resource exhaustion vulnerability in Android that can cause crash loops, leading to local denial of service. Attackers can exploi...

Aug 26, 2025
CVE-2025-38501
5.5

The Linux kernel's ksmbd SMB server component allows repeated connections from clients with the same IP address to exhaust maximum connection limits, ...

Aug 16, 2025
CVE-2025-40766
5.5

SINEC Traffic Analyzer versions before V3.0 run Docker containers without proper resource limits, allowing attackers to exhaust system resources and c...

Aug 12, 2025
CVE-2025-20616
5.5

This vulnerability in Intel Tiber Edge Platform's Edge Orchestrator software allows authenticated users to cause resource exhaustion through uncontrol...

May 13, 2025
CVE-2025-31251
5.5

This vulnerability allows processing a maliciously crafted media file to cause unexpected app termination or corrupt process memory. It affects Apple ...

May 12, 2025
CVE-2025-27087
5.5

A kernel vulnerability in Cray Operating System (COS) allows local attackers to trigger a Denial of Service condition. This affects systems running vu...

Apr 22, 2025
CVE-2025-29478
5.5

A local denial-of-service vulnerability in fluent-bit v3.7.2 allows attackers to crash the service by exploiting a flaw in the cfl_list_size function....

Apr 7, 2025
CVE-2025-24235
5.5

A memory initialization vulnerability in macOS allows remote attackers to cause application crashes or heap corruption. This affects macOS Ventura, Se...

Mar 31, 2025
CVE-2024-44192
5.5

This vulnerability allows malicious web content to cause unexpected process crashes in Apple's WebKit browser engine. It affects users of Safari and A...

Mar 10, 2025
CVE-2024-57672
5.5

A local denial-of-service vulnerability in Floodlight v1.2 allows attackers with local access to crash the controller via the Topology Manager, Topolo...

Feb 6, 2025
CVE-2025-24151
5.5

This macOS kernel memory corruption vulnerability allows malicious applications to cause system crashes or corrupt kernel memory, potentially leading ...

Jan 27, 2025
CVE-2018-9447
5.5

This vulnerability allows local attackers to crash emergency callback mode on Android devices due to a missing null check in the EmergencyCallbackMode...

Jan 17, 2025
CVE-2024-47535
5.5

This vulnerability in Netty allows attackers to cause denial of service by creating a large file that Netty attempts to load on Windows systems. When ...

Nov 12, 2024
CVE-2024-44176
5.5

This vulnerability involves an out-of-bounds access issue in Apple's image processing components that could cause denial-of-service. Attackers could e...

Sep 17, 2024
CVE-2024-44183
5.5

A logic error in Apple operating systems allows an app to cause a denial-of-service (DoS) by exploiting improper error handling. This vulnerability af...

Sep 17, 2024
CVE-2024-44154
5.5

A memory initialization vulnerability in macOS allows processing malicious files to cause unexpected application termination. This affects users runni...

Sep 17, 2024
CVE-2024-21163
5.5

This vulnerability in MySQL Server's optimizer component allows high-privileged attackers with network access to cause denial of service (server hangs...

Jul 16, 2024
CVE-2024-21161
5.5

This vulnerability in Oracle VM VirtualBox allows a low-privileged attacker with local access to a Linux host to cause a denial of service (DoS) by cr...

Jul 16, 2024
CVE-2024-35799
5.5

A NULL pointer dereference vulnerability in the AMD display driver component of the Linux kernel can cause a kernel crash when disabling a display str...

May 17, 2024
CVE-2026-23809
5.4

This vulnerability allows attackers to bypass Wi-Fi network isolation controls in multi-BSSID environments by adapting port-stealing techniques. Succe...

Mar 4, 2026
CVE-2025-53636
5.4

Open OnDemand users can flood system logs by generating repeated errors through the shell app, creating excessively large log files that consume disk ...

Jul 11, 2025
CVE-2026-21435
5.3

This vulnerability allows an attacker to cause denial of service in webtransport-go implementations by preventing WebTransport session closure. Attack...

Feb 12, 2026

About Resource Exhaustion (CWE-400)

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, leading to exhaustion.

Our database tracks 699 CVEs classified as CWE-400, with 21 rated critical and 459 rated high severity. The average CVSS score for Resource Exhaustion vulnerabilities is 7.0.

External reference: View CWE-400 on MITRE CWE →

Monitor Resource Exhaustion Vulnerabilities

Get alerted when new Resource Exhaustion CVEs affect your infrastructure.

Start Monitoring Free