CWE-400: Resource Exhaustion

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, leading to exhaustion.

695
Total CVEs
21
Critical
455
High
7.0
Avg CVSS

Yearly Trend

2026
73
2025
268
2024
171
2023
96
2022
32

Top Affected Vendors

1 Oracle 50
2 Microsoft 49
3 Apple 25
4 Fedoraproject 19
5 Linux 18
6 Google 17
7 Debian 16
8 Netapp 13
9 Apache 12
10 Juniper 11

All Resource Exhaustion CVEs (695)

CVE-2024-40634
7.5

An unauthenticated attacker can send a specially crafted large JSON payload to Argo CD's /api/webhook endpoint, causing excessive memory allocation th...

Jul 22, 2024
CVE-2024-39551
7.5

An unauthenticated attacker can send specific H.323 packets to Juniper SRX/MX Series devices, causing uncontrolled resource consumption that leads to ...

Jul 11, 2024
CVE-2024-39548
7.5

An unauthenticated attacker can send network traffic to Juniper Junos OS Evolved devices to cause uncontrolled memory consumption in the aftmand proce...

Jul 11, 2024
CVE-2024-21523
7.5

The 'images' npm package is vulnerable to Denial of Service (DoS) attacks when unexpected input types are provided to certain functions. Attackers can...

Jul 10, 2024
CVE-2024-21521
7.5

The @discordjs/opus package is vulnerable to Denial of Service (DoS) attacks where an attacker can crash the system by providing specially crafted inp...

Jul 10, 2024
CVE-2024-38068
7.5

This vulnerability allows attackers to cause a denial of service on Windows Online Certificate Status Protocol (OCSP) servers by sending specially cra...

Jul 9, 2024
CVE-2024-38031
7.5

This vulnerability allows attackers to cause a denial of service on Windows Online Certificate Status Protocol (OCSP) servers by sending specially cra...

Jul 9, 2024
CVE-2024-38015
7.5

CVE-2024-38015 is a denial-of-service vulnerability in Windows Remote Desktop Gateway (RD Gateway) that allows attackers to crash the service, disrupt...

Jul 9, 2024
CVE-2024-34750
7.5

This vulnerability in Apache Tomcat allows attackers to cause uncontrolled resource consumption through HTTP/2 connections. By sending excessive HTTP ...

Jul 3, 2024
CVE-2024-5013
7.5

An unauthenticated Denial of Service vulnerability in WhatsUp Gold allows attackers to force the application into the SetAdminPassword installation st...

Jun 25, 2024
CVE-2024-5011
7.5

An unauthenticated attacker can send specially crafted HTTP requests to the TestController Chart functionality in WhatsUp Gold, causing uncontrolled r...

Jun 25, 2024
CVE-2024-5216
7.5

This vulnerability in mintplex-labs/anything-llm allows attackers to cause a Denial of Service by creating users with excessively large usernames, whi...

Jun 25, 2024
CVE-2023-45196
7.5

This vulnerability allows unauthenticated remote attackers to cause denial of service by tricking Adminer/AdminerEvo into connecting to malicious serv...

Jun 24, 2024
CVE-2024-34688
7.5

This vulnerability in SAP NetWeaver AS Java allows attackers to perform denial-of-service attacks by exploiting unrestricted access to Meta Model Repo...

Jun 11, 2024
CVE-2024-33655
7.5

CVE-2024-33655, known as DNSBomb, is a DNS protocol vulnerability that allows remote attackers to cause denial of service by accumulating DNS queries ...

Jun 6, 2024
CVE-2021-47295
7.5

This vulnerability is a memory leak in the Linux kernel's traffic control subsystem. It allows attackers to cause denial of service by exhausting kern...

May 21, 2024
CVE-2024-34953
7.5

CVE-2024-34953 is a memory exhaustion vulnerability in taurusxin ncmdump v1.3.2 that allows attackers to cause Denial of Service (DoS) by supplying a ...

May 20, 2024
CVE-2024-5055
7.5

This vulnerability allows attackers to crash XAMPP servers on Windows by sending many incomplete HTTP requests, causing uncontrolled resource consumpt...

May 17, 2024
CVE-2024-5052
7.5

CVE-2024-5052 is a Denial of Service vulnerability in Cerberus Enterprise 8.0.10.3 web administration interface. Attackers can crash the service by fl...

May 17, 2024
CVE-2024-4436
7.5

This vulnerability is an incomplete fix for CVE-2022-41723 in the etcd package distributed with Red Hat OpenStack platform. It allows potential HTTP/2...

May 8, 2024
CVE-2024-4438
7.5

This vulnerability is an incomplete fix for the Rapid Reset HTTP/2 attack (CVE-2023-39325/CVE-2023-44487) in etcd packages distributed with Red Hat Op...

May 8, 2024
CVE-2023-27321
7.5

This vulnerability allows remote attackers to cause denial-of-service by sending excessive OPC UA ConditionRefresh requests to OPC Foundation UA .NET ...

May 7, 2024
CVE-2024-32663
7.5

CVE-2024-32663 is a memory exhaustion vulnerability in Suricata's HTTP/2 parser where small amounts of HTTP/2 traffic can cause excessive memory consu...

May 7, 2024
CVE-2024-4599
7.5

A remote denial of service vulnerability in LAN Messenger version 3.4.0 allows an attacker to crash the service by sending a long string continuously ...

May 7, 2024
CVE-2024-4549
7.5

A denial-of-service vulnerability in Delta Electronics DIAEnergie allows attackers to cause system restarts by sending specially crafted 'ICS Restart!...

May 6, 2024
CVE-2023-39477
7.5

This vulnerability allows unauthenticated remote attackers to cause denial-of-service by sending excessive OPC UA ConditionRefresh requests to Inducti...

May 3, 2024
CVE-2023-27334
7.5

This vulnerability allows remote attackers to cause a denial-of-service condition in Softing edgeConnector Siemens by sending excessive OPC UA Conditi...

May 3, 2024
CVE-2023-50685
7.5

A remote attacker can cause a denial of service in Hipcam Cameras RealServer v1.0 by sending a crafted script to the client_port parameter. This vulne...

May 2, 2024
CVE-2024-25355
7.5

s3-url-parser version 1.0.3 contains a denial of service vulnerability in its regexes component that allows attackers to cause resource exhaustion and...

May 1, 2024
CVE-2024-34045
7.5

This vulnerability is a denial-of-service flaw in O-RAN E2T's SCTP thread implementation where a malformed E2setup message can cause a crash when incr...

Apr 30, 2024
CVE-2024-2757
7.5

This vulnerability in PHP's mb_encode_mimeheader() function causes infinite loops when processing specific input patterns, leading to denial of servic...

Apr 29, 2024
CVE-2023-6596
7.5

CVE-2023-6596 is an incomplete fix for the Rapid Reset vulnerability (CVE-2023-44487/CVE-2023-39325) in OpenShift Container Platform. This allows atta...

Apr 25, 2024
CVE-2024-26212
7.5

This vulnerability in the DHCP Server Service allows an attacker to send specially crafted packets to cause a denial of service (DoS) condition, poten...

Apr 9, 2024
CVE-2023-47150
7.5

IBM Common Cryptographic Architecture (CCA) versions 7.0.0 through 7.5.36 contain a vulnerability in AES operation handling that could allow a remote ...

Mar 26, 2024
CVE-2023-5685
7.5

This vulnerability in XNIO's NotifierState can cause a stack overflow when notifier state chains become excessively large, leading to uncontrolled res...

Mar 22, 2024
CVE-2023-50967
7.5

CVE-2023-50967 is a denial-of-service vulnerability in latchset jose library versions through 11. Attackers can cause excessive CPU consumption by pro...

Mar 20, 2024
CVE-2024-26369
7.5

A vulnerability in FastDDS's HistoryQosPolicy component causes a SIGABRT (abort signal) when receiving DataWriter data, leading to denial of service. ...

Mar 19, 2024
CVE-2024-28854
7.5

This vulnerability allows attackers to perform a Slowloris-style denial-of-service attack against services using tls-listener with default configurati...

Mar 15, 2024
CVE-2024-26190
7.5

This vulnerability in Microsoft's QUIC protocol implementation allows attackers to cause denial of service by sending specially crafted network packet...

Mar 12, 2024
CVE-2024-21392
7.5

This vulnerability in .NET and Visual Studio allows attackers to cause a denial of service by sending specially crafted requests to affected systems. ...

Mar 12, 2024
CVE-2024-25269
7.5

A memory leak vulnerability in libheif's JpegEncoder::Encode function allows attackers to cause denial of service by exhausting system memory. This af...

Mar 5, 2024
CVE-2024-27354
7.5

This vulnerability in phpseclib allows attackers to cause denial of service by providing a malformed certificate with an extremely large prime number,...

Mar 1, 2024
CVE-2024-25398
7.5

Srelay v0.4.8p3 contains a vulnerability where specially crafted network payloads can trigger a denial of service condition, causing the SOCKS proxy s...

Feb 27, 2024
CVE-2024-25978
7.5

This vulnerability in Moodle's file picker unzip functionality allows attackers to cause denial of service by uploading specially crafted zip files th...

Feb 19, 2024
CVE-2024-24814
7.5

CVE-2024-24814 is a denial-of-service vulnerability in mod_auth_openidc where attackers can send specially crafted cookies with large integer values t...

Feb 13, 2024
CVE-2024-21342
7.5

This vulnerability in Windows DNS Client allows an attacker to cause a denial of service (DoS) condition by sending specially crafted DNS responses. A...

Feb 13, 2024
CVE-2024-24781
7.5

CVE-2024-24781 is an unauthenticated remote denial-of-service vulnerability where attackers can overwhelm a single Ethernet port with excessive traffi...

Feb 13, 2024
CVE-2024-24575
7.5

CVE-2024-24575 is a vulnerability in libgit2 where specially crafted inputs to the git_revparse_single function can cause an infinite loop, leading to...

Feb 6, 2024
CVE-2024-24762
7.5

CVE-2024-24762 is a regular expression denial of service (ReDoS) vulnerability in python-multipart, a streaming multipart parser for Python. Attackers...

Feb 5, 2024
CVE-2023-52425
7.5

This vulnerability in libexpat allows attackers to cause denial of service through resource consumption by sending specially crafted XML with large to...

Feb 4, 2024

About Resource Exhaustion (CWE-400)

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, leading to exhaustion.

Our database tracks 695 CVEs classified as CWE-400, with 21 rated critical and 455 rated high severity. The average CVSS score for Resource Exhaustion vulnerabilities is 7.0.

External reference: View CWE-400 on MITRE CWE →

Monitor Resource Exhaustion Vulnerabilities

Get alerted when new Resource Exhaustion CVEs affect your infrastructure.

Start Monitoring Free