CWE-400: Resource Exhaustion

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, leading to exhaustion.

695
Total CVEs
21
Critical
455
High
7.0
Avg CVSS

Yearly Trend

2026
73
2025
268
2024
171
2023
96
2022
32

Top Affected Vendors

1 Oracle 50
2 Microsoft 49
3 Apple 25
4 Fedoraproject 19
5 Linux 18
6 Google 17
7 Debian 16
8 Netapp 13
9 Apache 12
10 Juniper 11

All Resource Exhaustion CVEs (695)

CVE-2024-57079
7.5

This vulnerability is a prototype pollution flaw in the lib.deepMerge function of @zag-js/core v0.50.0 that allows attackers to supply crafted payload...

Feb 5, 2025
CVE-2024-57081
7.5

This CVE describes a prototype pollution vulnerability in underscore-contrib's lib.fromQuery function that allows attackers to manipulate JavaScript o...

Feb 5, 2025
CVE-2024-57085
7.5

This CVE describes a prototype pollution vulnerability in the deepMerge function of @stryker-mutator/util version 8.6.0, allowing attackers to cause D...

Feb 5, 2025
CVE-2024-57074
7.5

This CVE describes a prototype pollution vulnerability in the lib.merge function of xe-utils v3.5.31, which allows attackers to cause Denial of Servic...

Feb 5, 2025
CVE-2024-57075
7.5

This CVE describes a prototype pollution vulnerability in eazy-logger v4.0.1 that allows attackers to cause Denial of Service (DoS) by sending special...

Feb 5, 2025
CVE-2024-57076
7.5

A prototype pollution vulnerability in ajax-request v1.2.3 allows attackers to manipulate JavaScript object prototypes by sending crafted payloads to ...

Feb 5, 2025
CVE-2025-21087
7.5

This vulnerability allows attackers to cause resource exhaustion on F5 BIG-IP systems by sending specific traffic to SSL/TLS or DNSSEC configurations....

Feb 5, 2025
CVE-2025-20058
7.5

This vulnerability in F5 BIG-IP message routing profiles allows undisclosed traffic to cause excessive memory consumption, potentially leading to deni...

Feb 5, 2025
CVE-2024-56921
7.5

This vulnerability in Open5gs AMF allows remote attackers to cause a denial of service by sending specially crafted InitialUEMessage or Registration r...

Feb 3, 2025
CVE-2024-57519
7.5

A denial-of-service vulnerability in Open5GS v2.7.2 allows remote attackers to crash the service via the ogs_dbi_auth_info function. This affects all ...

Jan 28, 2025
CVE-2023-37022
7.5

Open5GS MME versions up to 2.6.4 contain a reachable assertion vulnerability in the UE Context Release Request packet handler. An attacker can send sp...

Jan 22, 2025
CVE-2023-37014
7.5

CVE-2023-37014 is a denial-of-service vulnerability in Open5GS MME where attackers can send malformed S1AP packets to crash the service. This affects ...

Jan 22, 2025
CVE-2024-24424
7.5

This vulnerability in Magma's decode_access_point_name_ie function allows attackers to trigger a reachable assertion via crafted NAS packets, causing ...

Jan 21, 2025
CVE-2025-21549
7.5

This vulnerability allows unauthenticated attackers to cause a denial of service (DoS) on Oracle WebLogic Server 14.1.1.0.0 by sending specially craft...

Jan 21, 2025
CVE-2025-21545
7.5

This vulnerability allows unauthenticated attackers to cause denial of service (DoS) attacks against Oracle PeopleSoft Enterprise PeopleTools by sendi...

Jan 21, 2025
CVE-2024-50953
7.5

This vulnerability in XINJE XL5E-16T programmable logic controllers allows attackers to send specially crafted Modbus messages that cause a denial of ...

Jan 15, 2025
CVE-2025-21330
7.5

This vulnerability in Windows Remote Desktop Services allows attackers to cause a denial of service by sending specially crafted requests to vulnerabl...

Jan 14, 2025
CVE-2025-21300
7.5

This vulnerability in Windows Universal Plug and Play (UPnP) Device Host service allows attackers to cause a denial of service by sending specially cr...

Jan 14, 2025
CVE-2025-21289
7.5

This vulnerability in Microsoft Message Queuing (MSMQ) allows attackers to cause a denial of service by sending specially crafted packets to vulnerabl...

Jan 14, 2025
CVE-2025-21290
7.5

This vulnerability in Microsoft Message Queuing (MSMQ) allows attackers to cause a denial of service by sending specially crafted packets to vulnerabl...

Jan 14, 2025
CVE-2025-21270
7.5

Microsoft Message Queuing (MSMQ) contains a denial-of-service vulnerability that allows attackers to crash the service by sending specially crafted pa...

Jan 14, 2025
CVE-2025-21251
7.5

This vulnerability in Microsoft Message Queuing (MSMQ) allows an attacker to cause a denial of service by sending specially crafted packets to the ser...

Jan 14, 2025
CVE-2025-21231
7.5

This vulnerability in IP Helper allows attackers to cause a denial of service condition on affected systems. It affects Windows systems with IP Helper...

Jan 14, 2025
CVE-2025-21218
7.5

This Windows Kerberos vulnerability allows attackers to cause denial of service by sending specially crafted requests to Kerberos services. It affects...

Jan 14, 2025
CVE-2025-21207
7.5

This vulnerability in Windows Connected Devices Platform Service (Cdpsvc) allows attackers to cause a denial of service condition on affected systems....

Jan 14, 2025
CVE-2024-57655
7.5

This vulnerability in OpenLink Virtuoso OpenSource allows attackers to cause denial of service by sending specially crafted SQL statements to the dfe_...

Jan 14, 2025
CVE-2024-55605
7.5

This vulnerability in Suricata allows attackers to cause a denial-of-service by sending specially crafted network traffic that triggers a stack overfl...

Jan 6, 2025
CVE-2024-11835
7.5

An uncontrolled resource consumption vulnerability in PlexTrac's WebSocket implementation allows attackers to cause denial of service by exhausting se...

Dec 13, 2024
CVE-2024-48989
7.5

A vulnerability in the PROFINET stack implementation of Bosch Rexroth IndraDrive allows attackers to cause denial of service by sending arbitrary UDP ...

Nov 13, 2024
CVE-2024-10466
7.5

A remote server can send a specially crafted push message that causes the browser's parent process to hang, making Firefox or Thunderbird unresponsive...

Oct 29, 2024
CVE-2024-49767
7.5

Werkzeug versions before 3.0.6 contain a resource exhaustion vulnerability in the MultiPartParser that handles multipart/form-data requests. Attackers...

Oct 25, 2024
CVE-2024-21536
7.5

A Denial of Service vulnerability in http-proxy-middleware allows attackers to crash Node.js servers by sending requests to specific paths. This affec...

Oct 19, 2024
CVE-2024-47497
7.5

An unauthenticated attacker can send specific HTTPS requests to Juniper Junos OS devices, causing uncontrolled process creation that leads to resource...

Oct 11, 2024
CVE-2024-7294
7.5

This vulnerability allows attackers to launch HTTP Denial-of-Service attacks against Progress Telerik Report Server by targeting anonymous endpoints t...

Oct 9, 2024
CVE-2024-43544
7.5

This vulnerability in Microsoft's Simple Certificate Enrollment Protocol (SCEP) allows attackers to cause denial of service by sending specially craft...

Oct 8, 2024
CVE-2024-43541
7.5

This vulnerability in Microsoft's Simple Certificate Enrollment Protocol (SCEP) allows attackers to cause denial of service by sending specially craft...

Oct 8, 2024
CVE-2024-38149
7.5

This vulnerability allows attackers to cause a denial of service (DoS) in BranchCache, a Windows feature that caches content from remote servers. Atta...

Oct 8, 2024
CVE-2024-43789
7.5

This vulnerability in Discourse allows authenticated users to create posts with many replies and then fetch them all at once, potentially causing deni...

Oct 7, 2024
CVE-2024-47850
7.5

CVE-2024-47850 is a vulnerability in CUPS cups-browsed that allows attackers to trigger HTTP POST requests to arbitrary destinations via a single IPP ...

Oct 4, 2024
CVE-2024-37125
7.5

Dell SmartFabric OS10 Software contains an uncontrolled resource consumption vulnerability that allows remote unauthenticated attackers to cause denia...

Sep 26, 2024
CVE-2024-31145
7.5

This CVE describes a vulnerability in Xen hypervisor's memory mapping logic for PCI devices with Reserved Memory Regions (RMRR) or Unity Mapping range...

Sep 25, 2024
CVE-2024-7254
7.5

This vulnerability allows attackers to cause a stack overflow by sending malicious Protocol Buffers data with deeply nested groups, potentially crashi...

Sep 19, 2024
CVE-2024-27874
7.5

This vulnerability allows remote attackers to cause denial-of-service conditions on affected Apple devices through improper state management. It affec...

Sep 17, 2024
CVE-2024-38236
7.5

This vulnerability allows attackers to cause a denial of service in the DHCP Server service by sending specially crafted packets. It affects Windows S...

Sep 10, 2024
CVE-2024-43647
7.5

This vulnerability affects multiple SIMATIC S7-200 SMART CPU models where improper handling of malformed TCP packets can cause denial of service. An u...

Sep 10, 2024
CVE-2024-8418
7.5

CVE-2024-8418 is a denial-of-service vulnerability in Aardvark-dns where an attacker can keep TCP connections open indefinitely, causing the DNS serve...

Sep 4, 2024
CVE-2024-7592
7.5

A denial-of-service vulnerability in CPython's http.cookies module where parsing cookies containing backslashes in quoted values triggers quadratic co...

Aug 19, 2024
CVE-2024-41727
7.5

This vulnerability affects BIG-IP tenants on specific hardware and virtual editions using Intel E810 SR-IOV NICs, where undisclosed traffic patterns c...

Aug 14, 2024
CVE-2024-38168
7.5

This CVE describes a denial of service vulnerability in .NET and Visual Studio where an attacker can cause affected systems to become unresponsive or ...

Aug 13, 2024
CVE-2024-41989
7.5

This vulnerability in Django's floatformat template filter allows attackers to cause denial of service through memory exhaustion by providing speciall...

Aug 7, 2024

About Resource Exhaustion (CWE-400)

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, leading to exhaustion.

Our database tracks 695 CVEs classified as CWE-400, with 21 rated critical and 455 rated high severity. The average CVSS score for Resource Exhaustion vulnerabilities is 7.0.

External reference: View CWE-400 on MITRE CWE →

Monitor Resource Exhaustion Vulnerabilities

Get alerted when new Resource Exhaustion CVEs affect your infrastructure.

Start Monitoring Free