CWE-400: Resource Exhaustion

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, leading to exhaustion.

705
Total CVEs
21
Critical
465
High
7.0
Avg CVSS

Yearly Trend

2026
73
2025
268
2024
171
2023
96
2022
32

Top Affected Vendors

1 Oracle 51
2 Microsoft 49
3 Apple 25
4 Fedoraproject 20
5 Google 18
6 Linux 18
7 Debian 16
8 Netapp 13
9 Apache 12
10 Juniper 11

All Resource Exhaustion CVEs (705)

CVE-2025-20370
4.9

This vulnerability allows authenticated Splunk users with the 'change_authentication' capability to send multiple LDAP bind requests to a specific int...

Oct 1, 2025
CVE-2025-41677
4.9

This vulnerability allows a high-privileged remote attacker to cause denial of service by exhausting system resources through rapid crafted POST reque...

Jul 21, 2025
CVE-2025-53023
4.9

This vulnerability in MySQL Server's replication component allows authenticated high-privileged attackers to cause a denial of service (DoS) by crashi...

Jul 15, 2025
CVE-2025-50099
4.9

This vulnerability in MySQL Server's InnoDB component allows authenticated high-privilege attackers to cause denial of service by crashing or hanging ...

Jul 15, 2025
CVE-2025-50101
4.9

A vulnerability in MySQL Server's optimizer component allows authenticated high-privilege attackers to cause denial of service by crashing or hanging ...

Jul 15, 2025
CVE-2025-50092
4.9

This vulnerability in MySQL Server's InnoDB component allows high-privileged attackers with network access to cause denial of service by crashing or h...

Jul 15, 2025
CVE-2025-50094
4.9

This vulnerability in Oracle MySQL Server allows high-privileged attackers with network access to cause denial of service by crashing or hanging the s...

Jul 15, 2025
CVE-2025-50088
4.9

This vulnerability in Oracle MySQL's InnoDB component allows authenticated high-privileged attackers to cause a denial of service (DoS) by crashing or...

Jul 15, 2025
CVE-2025-50077
4.9

This vulnerability in MySQL Server's InnoDB component allows authenticated high-privileged attackers to cause denial of service by crashing or hanging...

Jul 15, 2025
CVE-2025-50079
4.9

This vulnerability in MySQL Server's optimizer component allows authenticated high-privilege attackers to cause denial of service by crashing or hangi...

Jul 15, 2025
CVE-2024-21218
4.9

This vulnerability in MySQL Server's InnoDB component allows high-privileged attackers with network access to cause a denial of service (DoS) by crash...

Oct 15, 2024
CVE-2024-21207
4.9

This vulnerability in MySQL Server's InnoDB component allows high-privileged attackers with network access to cause a denial of service by crashing or...

Oct 15, 2024
CVE-2024-21203
4.9

This vulnerability in Oracle MySQL Server's Full-Text Search (FTS) component allows high-privileged attackers with network access to cause a denial of...

Oct 15, 2024
CVE-2024-37299
4.9

This vulnerability in Discourse allows attackers to submit extremely long tag group names in requests, which can cause resource exhaustion and reduce ...

Jul 30, 2024
CVE-2024-21185
4.9

This vulnerability in MySQL Server's InnoDB component allows authenticated high-privileged attackers to cause denial of service by crashing or hanging...

Jul 16, 2024
CVE-2024-21127
4.9

This vulnerability in MySQL Server allows high-privileged attackers with network access to cause a denial of service (DoS) by crashing or hanging the ...

Jul 16, 2024
CVE-2024-20996
4.9

This vulnerability in MySQL Server's InnoDB component allows authenticated high-privilege attackers to cause denial of service by crashing or hanging ...

Jul 16, 2024
CVE-2024-23443
4.9

This vulnerability allows high-privileged Kibana users with osquery pack creation permissions to upload malicious packs that could cause Kibana availa...

Jun 19, 2024
CVE-2024-4284
4.9

A vulnerability in mintplex-labs/anything-llm allows authenticated users with manager or admin privileges to cause a denial of service by modifying a ...

May 19, 2024
CVE-2021-47284
4.7

This vulnerability is a use-after-free bug in the Linux kernel's ISDN mISDN netjet driver that can cause a kernel panic during device probe failure. I...

May 21, 2024
CVE-2025-26500
4.6

A denial-of-service vulnerability in Wind River VxWorks 7 allows attackers to crash systems by sending specially crafted USB packets. This affects VxW...

Mar 21, 2025
CVE-2025-50103
4.4

A vulnerability in MySQL Server's LDAP authentication component allows high-privileged attackers with network access to cause denial of service by cra...

Jul 15, 2025
CVE-2025-50096
4.4

This vulnerability in MySQL Server's InnoDB component allows authenticated high-privileged attackers with local access to cause a denial of service (D...

Jul 15, 2025
CVE-2025-30704
4.4

A vulnerability in Oracle MySQL Server's Components Services allows high-privileged attackers with network access to cause a denial of service by cras...

Apr 15, 2025
CVE-2024-12345
4.4

This vulnerability in INW Krbyyyzo 25.2002 allows attackers to cause resource consumption (denial of service) by manipulating the 's' parameter in the...

Jan 27, 2025
CVE-2024-37535
4.4

This vulnerability in GNOME VTE allows an attacker to cause denial of service through excessive memory consumption by sending malicious window resize ...

Jun 9, 2024
CVE-2026-29049
4.3

This vulnerability in melange allows attackers to cause disk exhaustion on build runners by specifying malicious URIs in build configurations. The upd...

Mar 6, 2026
CVE-2025-5342
4.3

This CVE describes a ReDOS (Regular Expression Denial of Service) vulnerability in Zohocorp ManageEngine Exchange Reporter Plus. Attackers can cause d...

Oct 30, 2025
CVE-2025-11635
4.3

The Tomofun Furbo 360 pet camera has a file upload vulnerability that allows attackers to cause resource consumption (denial of service) through remot...

Oct 12, 2025
CVE-2025-7070
4.3

This vulnerability in IROAD Dashcam Q9 allows attackers on the local network to spam MFA pairing requests, potentially causing resource exhaustion or ...

Jul 4, 2025
CVE-2025-5897
4.3

This vulnerability in vue-cli's PWA plugin involves inefficient regular expression complexity in the HtmlPwaPlugin component. Attackers can cause deni...

Jun 9, 2025
CVE-2025-3986
4.3

This vulnerability in Apereo CAS 5.2.6 involves inefficient regular expression complexity in the CasConfigurationMetadataServerController.java file, a...

Apr 27, 2025
CVE-2024-25132
4.3

A denial-of-service vulnerability in OpenShift Dedicated's Hive hibernation controller allows attackers to crash the controller by creating malformed ...

Mar 19, 2025
CVE-2024-34036
4.3

This vulnerability allows attackers to disrupt the initial connection between a gNB (gNodeB) and the Near Real-Time RAN Intelligent Controller (Near R...

Feb 25, 2025
CVE-2024-53851
4.3

This vulnerability in Discourse allows authenticated users to send excessive URL requests to the inline onebox generation endpoint, causing denial of ...

Feb 4, 2025
CVE-2024-42426
4.3

Dell PowerScale OneFS versions 9.5.0.x through 9.8.0.x contain an uncontrolled resource consumption vulnerability. A low-privilege remote attacker cou...

Dec 9, 2024
CVE-2024-47554
4.3

This vulnerability in Apache Commons IO allows attackers to cause denial of service by consuming excessive CPU resources through maliciously crafted i...

Oct 3, 2024
CVE-2024-41434
4.3

A buffer overflow vulnerability exists in PingCAP TiDB v8.1.0's (*Column).GetDecimal component when processing crafted queries involving RemoveUnneces...

Sep 3, 2024
CVE-2024-21658
4.3

CVE-2024-21658 is a resource exhaustion vulnerability in the discourse-calendar plugin where overly generous region value length limits allow attacker...

Aug 30, 2024
CVE-2024-7610
4.3

This vulnerability allows attackers to cause a Denial of Service (DoS) condition in GitLab by exploiting catastrophic backtracking when parsing Elasti...

Aug 8, 2024
CVE-2026-27576
4.0

OpenClaw's ACP bridge accepts excessively large prompt text blocks, allowing local ACP clients to send oversized payloads that could cause resource ex...

Feb 21, 2026
CVE-2026-0992
2.9

This vulnerability in libxml2 allows remote attackers to cause denial-of-service by sending crafted XML catalogs with repeated <nextCatalog> elements ...

Jan 15, 2026
CVE-2025-66861
2.5

A vulnerability in BinUtils' cp-demangle.c function allows attackers to cause denial of service through specially crafted PE files. This affects syste...

Dec 29, 2025
CVE-2025-55102
N/A

This CVE describes a denial-of-service vulnerability in Eclipse ThreadX NetX Duo's IPv6 component where sending a specially crafted 'Packet Too Big' I...

Jan 27, 2026
CVE-2026-22541
N/A

This vulnerability allows attackers to cause a denial of service on EV charger control boards by flooding them with ICMP requests. When exploited, the...

Jan 7, 2026
CVE-2026-22542
N/A

This vulnerability allows an attacker on the internal network to cause a denial of service by establishing two concurrent Telnet connections to the sy...

Jan 7, 2026
CVE-2026-22540
N/A

This vulnerability allows attackers to cause a denial of service on electric vehicle charger control boards by flooding them with ARP requests. When e...

Jan 7, 2026
CVE-2023-53873
N/A

SyncBreeze 15.2.24 contains a denial of service vulnerability where attackers can crash the service by sending oversized password parameters with repe...

Dec 15, 2025
CVE-2025-67731
N/A

Servify Express versions before 1.2 have a denial-of-service vulnerability where attackers can send extremely large JSON request bodies, causing exces...

Dec 12, 2025
CVE-2024-58306
N/A

CVE-2024-58306 is a denial of service vulnerability in minaliC 2.0.0 that allows remote attackers to crash the web server by sending oversized GET req...

Dec 11, 2025

About Resource Exhaustion (CWE-400)

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, leading to exhaustion.

Our database tracks 705 CVEs classified as CWE-400, with 21 rated critical and 465 rated high severity. The average CVSS score for Resource Exhaustion vulnerabilities is 7.0.

External reference: View CWE-400 on MITRE CWE →

Monitor Resource Exhaustion Vulnerabilities

Get alerted when new Resource Exhaustion CVEs affect your infrastructure.

Start Monitoring Free