CWE-400: Resource Exhaustion

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, leading to exhaustion.

695
Total CVEs
21
Critical
455
High
7.0
Avg CVSS

Yearly Trend

2026
73
2025
268
2024
171
2023
96
2022
32

Top Affected Vendors

1 Oracle 50
2 Microsoft 49
3 Apple 25
4 Fedoraproject 19
5 Linux 18
6 Google 17
7 Debian 16
8 Netapp 13
9 Apache 12
10 Juniper 11

All Resource Exhaustion CVEs (695)

CVE-2023-30999
7.5

This vulnerability in IBM Security Access Manager Container allows attackers to cause denial of service through uncontrolled resource consumption. It ...

Feb 3, 2024
CVE-2024-22233
7.5

This vulnerability in Spring Framework allows attackers to cause denial-of-service (DoS) conditions by sending specially crafted HTTP requests. Applic...

Jan 22, 2024
CVE-2024-23744
7.5

A vulnerability in Mbed TLS 3.5.1 causes persistent handshake denial when a client sends a TLS 1.3 ClientHello message without extensions. This allows...

Jan 21, 2024
CVE-2023-22512
7.5

This is a high-severity denial-of-service vulnerability in Confluence Data Center and Server that allows unauthenticated attackers to disrupt service ...

Jan 16, 2024
CVE-2023-52113
7.5

The CVE-2023-52113 vulnerability, known as launchAnyWhere, is a flaw in the ActivityManagerService module that allows attackers to trigger denial-of-s...

Jan 16, 2024
CVE-2024-22362
7.5

This CVE describes a vulnerability in Drupal's handling of structural elements that could allow an attacker to trigger a denial-of-service condition. ...

Jan 16, 2024
CVE-2023-34061
7.5

This vulnerability allows unauthenticated attackers to trigger route pruning in Cloud Foundry's gorouter, causing denial of service by degrading servi...

Jan 12, 2024
CVE-2024-20672
7.5

This CVE describes a denial of service vulnerability in .NET that allows attackers to crash affected applications by sending specially crafted request...

Jan 9, 2024
CVE-2024-0241
7.5

CVE-2024-0241 is an uncontrolled resource consumption vulnerability in encoded_id-rails gem versions before 1.0.0.beta2. Remote unauthenticated attack...

Jan 4, 2024
CVE-2023-49550
7.5

A denial-of-service vulnerability in Cesanta mjs 2.20.0 allows remote attackers to crash applications using this embedded JavaScript engine via a spec...

Jan 2, 2024
CVE-2023-50020
7.5

This vulnerability in open5gs v2.6.6 allows attackers to crash the AMF (Access and Mobility Management Function) component by exploiting SIGPIPE signa...

Jan 2, 2024
CVE-2023-50730
7.5

Grackle GraphQL server versions before 0.18.0 contain two stack overflow vulnerabilities. Attackers can craft malicious GraphQL queries with cyclic fr...

Dec 22, 2023
CVE-2023-50249
7.5

A Regular Expression Denial of Service (ReDoS) vulnerability in Sentry's Astro SDK allows attackers to cause excessive server computation times, leadi...

Dec 20, 2023
CVE-2023-49140
7.5

This vulnerability allows remote unauthenticated attackers to cause denial-of-service conditions in HMI GC-A2 series devices by sending specially craf...

Dec 12, 2023
CVE-2023-49713
7.5

This vulnerability allows remote unauthenticated attackers to cause a denial-of-service condition in HMI GC-A2 series devices by sending specially cra...

Dec 12, 2023
CVE-2023-48840
7.5

This vulnerability in Appointment Scheduler 3.0 allows attackers to send unlimited AJAX requests to the pjActionAjaxSend endpoint, causing resource ex...

Dec 7, 2023
CVE-2023-48833
7.5

This vulnerability in Time Slots Booking Calendar 4.0 allows attackers to send unlimited AJAX requests to the pjActionAJaxSend endpoint, causing resou...

Dec 7, 2023
CVE-2023-47633
7.5

Traefik's Docker integration creates an automatic route where Traefik serves as its own backend, causing 100% CPU consumption in a denial-of-service c...

Dec 4, 2023
CVE-2023-48951
7.5

A vulnerability in the box_equal function of OpenLink Virtuoso OpenSource v7.2.11 allows attackers to cause Denial of Service (DoS) by executing a SEL...

Nov 29, 2023
CVE-2023-45622
7.5

Unauthenticated attackers can exploit vulnerabilities in the BLE daemon service via the PAPI protocol to cause Denial-of-Service (DoS) on affected Aru...

Nov 14, 2023
CVE-2023-5759
7.5

This vulnerability allows unauthenticated remote attackers to cause a Denial of Service (DoS) in Helix Core servers by exploiting a buffer-related iss...

Nov 8, 2023
CVE-2023-45319
7.5

This vulnerability allows unauthenticated remote attackers to cause a Denial of Service (DoS) in Helix Core servers by exploiting the commit function....

Nov 8, 2023
CVE-2023-35767
7.5

This vulnerability allows unauthenticated remote attackers to trigger a shutdown function in Helix Core servers, causing denial of service. All Helix ...

Nov 8, 2023
CVE-2023-41378
7.5

This vulnerability allows an attacker to cause a denial of service in Calico Typha by initiating a malicious TLS handshake that blocks the server's ma...

Nov 6, 2023
CVE-2023-21339
7.5

This vulnerability in Minikin (Android's text layout engine) allows remote attackers to cause denial of service through resource exhaustion by sending...

Oct 30, 2023
CVE-2023-31418
7.5

CVE-2023-31418 is a denial-of-service vulnerability in Elasticsearch's HTTP layer where unauthenticated attackers can cause nodes to crash with OutOfM...

Oct 26, 2023
CVE-2023-5724
7.5

This vulnerability in Mozilla graphics drivers allows attackers to cause denial of service through large draw calls. It affects Firefox versions befor...

Oct 25, 2023
CVE-2023-44388
7.5

CVE-2023-44388 is a denial-of-service vulnerability in Discourse where malicious requests can rapidly fill production log files, causing servers to ru...

Oct 16, 2023
CVE-2023-40180
7.5

This vulnerability in silverstripe-graphql allows attackers to execute recursive GraphQL queries causing Distributed Denial of Service (DDoS) attacks....

Oct 16, 2023
CVE-2022-43740
7.5

This vulnerability in IBM Security Verify Access OIDC Provider allows remote attackers to cause denial of service through uncontrolled resource consum...

Oct 14, 2023
CVE-2023-36841
7.5

An unauthenticated network attacker can send malformed TCP traffic to cause an infinite loop in the Packet Forwarding Engine on Juniper MX Series rout...

Oct 12, 2023
CVE-2023-36606
7.5

CVE-2023-36606 is a denial-of-service vulnerability in Microsoft Message Queuing (MSMQ) where an unauthenticated attacker could send specially crafted...

Oct 10, 2023
CVE-2023-36703
7.5

This vulnerability in the DHCP Server Service allows an attacker to send specially crafted packets that cause a denial of service, potentially crashin...

Oct 10, 2023
CVE-2023-44487
7.5

CVE-2023-44487 is an HTTP/2 protocol vulnerability that allows attackers to cause denial of service by rapidly resetting streams, consuming server res...

Oct 10, 2023
CVE-2023-43810
7.5

This vulnerability in OpenTelemetry Python autoinstrumentation allows attackers to cause memory exhaustion by sending HTTP requests with random, long ...

Oct 6, 2023
CVE-2023-5157
7.5

A vulnerability in MariaDB allows remote attackers to cause denial of service via port scans on ports 3306 and 4567. This affects MariaDB servers with...

Sep 27, 2023
CVE-2023-42457
7.5

This CVE describes a denial-of-service vulnerability in plone.rest where repeated use of the `++api++` traverser in URLs causes increasing processing ...

Sep 21, 2023
CVE-2023-42522
7.5

This vulnerability allows remote attackers to crash the scanning engine in multiple WithSecure security products by sending a specially crafted PE fil...

Sep 18, 2023
CVE-2023-42520
7.5

This vulnerability allows remote attackers to crash the scanning engine in multiple WithSecure security products by sending specially crafted data fil...

Sep 18, 2023
CVE-2023-26141
7.5

This vulnerability in Sidekiq versions before 7.1.3 allows attackers to cause a Denial of Service (DoS) by manipulating localStorage values in the das...

Sep 14, 2023
CVE-2023-40591
7.5

This vulnerability in go-ethereum (geth) allows attackers to send specially crafted P2P messages that cause vulnerable nodes to consume unbounded amou...

Sep 6, 2023
CVE-2023-41121
7.5

This vulnerability in Array AG OS allows remote attackers to cause denial of service by crashing system service processes through abnormal HTTP operat...

Aug 25, 2023
CVE-2023-41173
7.5

AdGuard DNS versions before 2.2 contain a vulnerability where remote attackers can send malformed UDP packets to cause denial of service. This affects...

Aug 25, 2023
CVE-2020-26652
7.5

This vulnerability in the rtl8812au Wi-Fi driver allows attackers to cause a denial of service by exploiting a flaw in the nl80211_send_chandef functi...

Aug 22, 2023
CVE-2020-20813
7.5

This vulnerability in OpenVPN allows remote attackers to send crafted reset packets through the control channel, causing a denial of service (DoS) con...

Aug 22, 2023
CVE-2023-38741
7.5

IBM TXSeries for Multiplatforms versions 8.1, 8.2, and 9.1 are vulnerable to a denial of service attack due to improper timeout enforcement on read op...

Aug 14, 2023
CVE-2023-38180
7.5

This CVE describes a denial of service vulnerability in .NET and Visual Studio that allows attackers to crash affected applications by sending special...

Aug 8, 2023
CVE-2023-3825
7.5

This vulnerability in PTC's KEPServerEX allows attackers to send specially crafted OPC UA messages containing recursively defined objects, causing unc...

Jul 31, 2023
CVE-2023-38200
7.5

This vulnerability in Keylime's registrar component allows remote attackers to cause a denial of service by exhausting all available SSL connections d...

Jul 24, 2023
CVE-2023-37475
7.5

CVE-2023-37475 is a denial-of-service vulnerability in the Hamba avro Go library where a maliciously crafted string passed to the Unmarshal() function...

Jul 17, 2023

About Resource Exhaustion (CWE-400)

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, leading to exhaustion.

Our database tracks 695 CVEs classified as CWE-400, with 21 rated critical and 455 rated high severity. The average CVSS score for Resource Exhaustion vulnerabilities is 7.0.

External reference: View CWE-400 on MITRE CWE →

Monitor Resource Exhaustion Vulnerabilities

Get alerted when new Resource Exhaustion CVEs affect your infrastructure.

Start Monitoring Free