CWE-400: Resource Exhaustion
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, leading to exhaustion.
Yearly Trend
Top Affected Vendors
All Resource Exhaustion CVEs (695)
This vulnerability is a prototype pollution flaw in the lib.deepMerge function of @zag-js/core v0.50.0 that allows attackers to supply crafted payload...
Feb 5, 2025This CVE describes a prototype pollution vulnerability in underscore-contrib's lib.fromQuery function that allows attackers to manipulate JavaScript o...
Feb 5, 2025This CVE describes a prototype pollution vulnerability in the deepMerge function of @stryker-mutator/util version 8.6.0, allowing attackers to cause D...
Feb 5, 2025This CVE describes a prototype pollution vulnerability in the lib.merge function of xe-utils v3.5.31, which allows attackers to cause Denial of Servic...
Feb 5, 2025This CVE describes a prototype pollution vulnerability in eazy-logger v4.0.1 that allows attackers to cause Denial of Service (DoS) by sending special...
Feb 5, 2025A prototype pollution vulnerability in ajax-request v1.2.3 allows attackers to manipulate JavaScript object prototypes by sending crafted payloads to ...
Feb 5, 2025This vulnerability allows attackers to cause resource exhaustion on F5 BIG-IP systems by sending specific traffic to SSL/TLS or DNSSEC configurations....
Feb 5, 2025This vulnerability in F5 BIG-IP message routing profiles allows undisclosed traffic to cause excessive memory consumption, potentially leading to deni...
Feb 5, 2025This vulnerability in Open5gs AMF allows remote attackers to cause a denial of service by sending specially crafted InitialUEMessage or Registration r...
Feb 3, 2025A denial-of-service vulnerability in Open5GS v2.7.2 allows remote attackers to crash the service via the ogs_dbi_auth_info function. This affects all ...
Jan 28, 2025Open5GS MME versions up to 2.6.4 contain a reachable assertion vulnerability in the UE Context Release Request packet handler. An attacker can send sp...
Jan 22, 2025CVE-2023-37014 is a denial-of-service vulnerability in Open5GS MME where attackers can send malformed S1AP packets to crash the service. This affects ...
Jan 22, 2025This vulnerability in Magma's decode_access_point_name_ie function allows attackers to trigger a reachable assertion via crafted NAS packets, causing ...
Jan 21, 2025This vulnerability allows unauthenticated attackers to cause a denial of service (DoS) on Oracle WebLogic Server 14.1.1.0.0 by sending specially craft...
Jan 21, 2025This vulnerability allows unauthenticated attackers to cause denial of service (DoS) attacks against Oracle PeopleSoft Enterprise PeopleTools by sendi...
Jan 21, 2025This vulnerability in XINJE XL5E-16T programmable logic controllers allows attackers to send specially crafted Modbus messages that cause a denial of ...
Jan 15, 2025This vulnerability in Windows Remote Desktop Services allows attackers to cause a denial of service by sending specially crafted requests to vulnerabl...
Jan 14, 2025This vulnerability in Windows Universal Plug and Play (UPnP) Device Host service allows attackers to cause a denial of service by sending specially cr...
Jan 14, 2025This vulnerability in Microsoft Message Queuing (MSMQ) allows attackers to cause a denial of service by sending specially crafted packets to vulnerabl...
Jan 14, 2025This vulnerability in Microsoft Message Queuing (MSMQ) allows attackers to cause a denial of service by sending specially crafted packets to vulnerabl...
Jan 14, 2025Microsoft Message Queuing (MSMQ) contains a denial-of-service vulnerability that allows attackers to crash the service by sending specially crafted pa...
Jan 14, 2025This vulnerability in Microsoft Message Queuing (MSMQ) allows an attacker to cause a denial of service by sending specially crafted packets to the ser...
Jan 14, 2025This vulnerability in IP Helper allows attackers to cause a denial of service condition on affected systems. It affects Windows systems with IP Helper...
Jan 14, 2025This Windows Kerberos vulnerability allows attackers to cause denial of service by sending specially crafted requests to Kerberos services. It affects...
Jan 14, 2025This vulnerability in Windows Connected Devices Platform Service (Cdpsvc) allows attackers to cause a denial of service condition on affected systems....
Jan 14, 2025This vulnerability in OpenLink Virtuoso OpenSource allows attackers to cause denial of service by sending specially crafted SQL statements to the dfe_...
Jan 14, 2025This vulnerability in Suricata allows attackers to cause a denial-of-service by sending specially crafted network traffic that triggers a stack overfl...
Jan 6, 2025An uncontrolled resource consumption vulnerability in PlexTrac's WebSocket implementation allows attackers to cause denial of service by exhausting se...
Dec 13, 2024A vulnerability in the PROFINET stack implementation of Bosch Rexroth IndraDrive allows attackers to cause denial of service by sending arbitrary UDP ...
Nov 13, 2024A remote server can send a specially crafted push message that causes the browser's parent process to hang, making Firefox or Thunderbird unresponsive...
Oct 29, 2024Werkzeug versions before 3.0.6 contain a resource exhaustion vulnerability in the MultiPartParser that handles multipart/form-data requests. Attackers...
Oct 25, 2024A Denial of Service vulnerability in http-proxy-middleware allows attackers to crash Node.js servers by sending requests to specific paths. This affec...
Oct 19, 2024An unauthenticated attacker can send specific HTTPS requests to Juniper Junos OS devices, causing uncontrolled process creation that leads to resource...
Oct 11, 2024This vulnerability allows attackers to launch HTTP Denial-of-Service attacks against Progress Telerik Report Server by targeting anonymous endpoints t...
Oct 9, 2024This vulnerability in Microsoft's Simple Certificate Enrollment Protocol (SCEP) allows attackers to cause denial of service by sending specially craft...
Oct 8, 2024This vulnerability in Microsoft's Simple Certificate Enrollment Protocol (SCEP) allows attackers to cause denial of service by sending specially craft...
Oct 8, 2024This vulnerability allows attackers to cause a denial of service (DoS) in BranchCache, a Windows feature that caches content from remote servers. Atta...
Oct 8, 2024This vulnerability in Discourse allows authenticated users to create posts with many replies and then fetch them all at once, potentially causing deni...
Oct 7, 2024CVE-2024-47850 is a vulnerability in CUPS cups-browsed that allows attackers to trigger HTTP POST requests to arbitrary destinations via a single IPP ...
Oct 4, 2024Dell SmartFabric OS10 Software contains an uncontrolled resource consumption vulnerability that allows remote unauthenticated attackers to cause denia...
Sep 26, 2024This CVE describes a vulnerability in Xen hypervisor's memory mapping logic for PCI devices with Reserved Memory Regions (RMRR) or Unity Mapping range...
Sep 25, 2024This vulnerability allows attackers to cause a stack overflow by sending malicious Protocol Buffers data with deeply nested groups, potentially crashi...
Sep 19, 2024This vulnerability allows remote attackers to cause denial-of-service conditions on affected Apple devices through improper state management. It affec...
Sep 17, 2024This vulnerability allows attackers to cause a denial of service in the DHCP Server service by sending specially crafted packets. It affects Windows S...
Sep 10, 2024This vulnerability affects multiple SIMATIC S7-200 SMART CPU models where improper handling of malformed TCP packets can cause denial of service. An u...
Sep 10, 2024CVE-2024-8418 is a denial-of-service vulnerability in Aardvark-dns where an attacker can keep TCP connections open indefinitely, causing the DNS serve...
Sep 4, 2024A denial-of-service vulnerability in CPython's http.cookies module where parsing cookies containing backslashes in quoted values triggers quadratic co...
Aug 19, 2024This vulnerability affects BIG-IP tenants on specific hardware and virtual editions using Intel E810 SR-IOV NICs, where undisclosed traffic patterns c...
Aug 14, 2024This CVE describes a denial of service vulnerability in .NET and Visual Studio where an attacker can cause affected systems to become unresponsive or ...
Aug 13, 2024This vulnerability in Django's floatformat template filter allows attackers to cause denial of service through memory exhaustion by providing speciall...
Aug 7, 2024About Resource Exhaustion (CWE-400)
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, leading to exhaustion.
Our database tracks 695 CVEs classified as CWE-400, with 21 rated critical and 455 rated high severity. The average CVSS score for Resource Exhaustion vulnerabilities is 7.0.
External reference: View CWE-400 on MITRE CWE →
Monitor Resource Exhaustion Vulnerabilities
Get alerted when new Resource Exhaustion CVEs affect your infrastructure.
Start Monitoring Free