CWE-400: Resource Exhaustion
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, leading to exhaustion.
Yearly Trend
Top Affected Vendors
All Resource Exhaustion CVEs (695)
This vulnerability in the MediaWiki IPInfo extension allows attackers to cause excessive resource consumption through uncontrolled allocation. It affe...
Jul 4, 2025CVE-2025-52887 is a memory exhaustion vulnerability in cpp-httplib where excessive HTTP headers cause memory leaks when connections disconnect, potent...
Jun 26, 2025This vulnerability in Liferay Portal and DXP allows remote attackers to cause denial-of-service by consuming system memory through crafted HTTP reques...
Jun 16, 2025This vulnerability allows remote attackers to perform denial-of-service attacks on Liferay Portal/DXP by sending complex GraphQL queries that overwhel...
Jun 16, 2025This vulnerability in Windows Standards-Based Storage Management Service allows unauthorized attackers to cause denial of service by consuming system ...
Jun 10, 2025This vulnerability allows an unauthorized attacker to cause a denial of service (DoS) in Windows LSASS (Local Security Authority Subsystem Service) by...
Jun 10, 2025Dell PowerScale OneFS versions 9.4.0.0 through 9.9.0.0 contain an uncontrolled resource consumption vulnerability. A remote unauthenticated attacker c...
May 15, 2025A vulnerability in Samsung's RRC (Radio Resource Control) implementation across multiple Exynos processors allows incorrect handling of undefined valu...
May 14, 2025This vulnerability allows attackers to cause Denial of Service (DoS) by sending specially crafted Discovery messages that trigger excessive memory all...
May 12, 2025This vulnerability in Rack's query parser allows attackers to send HTTP requests with extremely large numbers of parameters, causing memory exhaustion...
May 7, 2025This vulnerability allows unauthenticated attackers to cause a denial of service (DoS) in Oracle Application Object Library by sending specially craft...
Apr 15, 2025CVE-2025-27485 is a denial-of-service vulnerability in Windows Standards-Based Storage Management Service that allows unauthorized attackers to exhaus...
Apr 8, 2025This vulnerability in Windows HTTP.sys allows unauthorized attackers to cause denial of service by consuming excessive resources. It affects Windows s...
Apr 8, 2025This vulnerability in Windows Standards-Based Storage Management Service allows unauthorized attackers to cause denial of service by consuming system ...
Apr 8, 2025This vulnerability in Windows Standards-Based Storage Management Service allows unauthorized attackers to cause denial of service by consuming system ...
Apr 8, 2025This vulnerability allows an unauthorized attacker to cause a denial of service (DoS) on Windows systems by exploiting uncontrolled resource consumpti...
Apr 8, 2025This vulnerability allows unauthorized attackers to cause denial of service in Windows Standards-Based Storage Management Service by consuming system ...
Apr 8, 2025This vulnerability in Windows Cryptographic Services allows attackers to cause denial of service by consuming system resources through network request...
Apr 8, 2025This vulnerability in Windows Standards-Based Storage Management Service allows unauthorized attackers to cause denial of service by consuming system ...
Apr 8, 2025This vulnerability allows attackers to send very large payloads to Snowplow Collector 3.x servers, causing them to become unresponsive and potentially...
Apr 3, 2025CVE-2025-2586 is an unauthenticated API request flooding vulnerability in OpenShift Lightspeed Service. Attackers can send repeated queries to non-exi...
Mar 31, 2025CVE-2025-29487 is an out-of-memory vulnerability in libming's parseABC_STRING_INFO function that allows attackers to trigger allocator exhaustion, lea...
Mar 27, 2025CVE-2025-29484 is an out-of-memory vulnerability in libming's parseABC_NS_SET_INFO function that allows attackers to trigger allocator exhaustion, lea...
Mar 27, 2025Redlib versions before 0.36.0 contain a vulnerability where attackers can cause denial-of-service by submitting specially crafted base2048-encoded DEF...
Mar 20, 2025A Denial of Service vulnerability in gradio-app/gradio version 0.39.1 allows attackers to crash servers by uploading files with excessively long filen...
Mar 20, 2025An unauthenticated attacker can cause denial-of-service by submitting excessively large text in the 'name' field during signup, making the Admin panel...
Mar 20, 2025An unauthenticated Denial of Service vulnerability exists in netease-youdao/qanything v2.0.0 where attackers can send file upload requests with excess...
Mar 20, 2025This vulnerability in open-webui/open-webui allows unauthenticated attackers to submit extremely large payloads in email and password fields during si...
Mar 20, 2025A Denial of Service vulnerability in the brycedrennan/imaginairy repository allows attackers to crash the server by sending invalid requests to the /a...
Mar 20, 2025This vulnerability allows unauthenticated attackers to cause denial of service by sending file upload requests with excessively large filenames to the...
Mar 20, 2025A Denial of Service vulnerability in imartinez/privategpt v0.6.2 allows attackers to crash the server by uploading files with excessively long filenam...
Mar 20, 2025A Denial of Service vulnerability in InvokeAI allows attackers to crash the web interface by sending oversized payloads to board update endpoints. Thi...
Mar 20, 2025A Denial of Service (DoS) vulnerability in lm-sys/fastchat version 0.2.36 allows attackers to crash the server by uploading a file with an excessively...
Mar 20, 2025CVE-2025-29907 is a denial-of-service vulnerability in jsPDF library where attackers can pass malicious data URLs to addImage, html, or addSvgAsImage ...
Mar 18, 2025This vulnerability in ruby-saml allows remote attackers to cause Denial of Service (DoS) by sending specially crafted compressed SAML responses. The l...
Mar 12, 2025An unauthenticated attacker can cause a Denial of Service (DoS) in Palo Alto Networks PAN-OS GlobalProtect by sending specially crafted packets over t...
Mar 12, 2025This CVE describes a memory handling vulnerability in Apple operating systems that could allow a malicious app to cause system crashes or corrupt kern...
Mar 10, 2025This vulnerability allows a malicious application to cause kernel memory corruption or system crashes on macOS systems. It affects macOS users running...
Mar 10, 2025Sysax Multi Server 6.99 is vulnerable to denial of service when processing malicious SSH packets, causing service disruption. This affects organizatio...
Mar 5, 2025This vulnerability in Vasion Print (formerly PrinterLogic) allows remote attackers to perform network scanning and cause denial-of-service conditions....
Mar 5, 2025A critical goroutine leak vulnerability in Abacus server's Server-Sent Events implementation allows resource exhaustion when clients disconnect from t...
Mar 3, 2025GraphQL Mesh has a variable caching vulnerability where initial GraphQL query variables persist across subsequent requests with different variables un...
Feb 20, 2025This vulnerability allows attackers to send excessive password reset and email change requests to legitimate users, potentially causing denial of serv...
Feb 20, 2025This vulnerability allows attackers to abuse the 'Forgot Password' feature in PHPJabbers Bus Reservation System v1.1 by sending excessive password res...
Feb 20, 2025This vulnerability allows attackers to send unlimited password reset requests for legitimate users in PHPJabbers Hotel Booking System v4.0, potentiall...
Feb 19, 2025This vulnerability allows attackers to send excessive password reset or email change requests to legitimate users, potentially causing email denial-of...
Feb 19, 2025A vulnerability in LearnDash v6.7.1 allows attackers to cause Denial of Service (DoS) by uploading excessive files through the profile image upload fu...
Feb 12, 2025A missing null pointer check in the Xclipse GPU driver for Samsung Exynos mobile processors allows attackers to cause denial of service. This affects ...
Feb 12, 2025This vulnerability in Windows Active Directory Domain Services API allows attackers to cause a denial of service condition by sending specially crafte...
Feb 11, 2025A denial-of-service vulnerability in Microsoft Message Queuing (MSMQ) allows attackers to crash the service by sending specially crafted messages. Thi...
Feb 11, 2025About Resource Exhaustion (CWE-400)
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, leading to exhaustion.
Our database tracks 695 CVEs classified as CWE-400, with 21 rated critical and 455 rated high severity. The average CVSS score for Resource Exhaustion vulnerabilities is 7.0.
External reference: View CWE-400 on MITRE CWE →
Monitor Resource Exhaustion Vulnerabilities
Get alerted when new Resource Exhaustion CVEs affect your infrastructure.
Start Monitoring Free