CWE-400: Resource Exhaustion

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, leading to exhaustion.

695
Total CVEs
21
Critical
455
High
7.0
Avg CVSS

Yearly Trend

2026
73
2025
268
2024
171
2023
96
2022
32

Top Affected Vendors

1 Oracle 50
2 Microsoft 49
3 Apple 25
4 Fedoraproject 19
5 Linux 18
6 Google 17
7 Debian 16
8 Netapp 13
9 Apache 12
10 Juniper 11

All Resource Exhaustion CVEs (695)

CVE-2023-35945
7.5

Envoy's HTTP/2 implementation has a memory leak vulnerability when receiving RST_STREAM followed by GOAWAY frames from upstream servers. This allows a...

Jul 13, 2023
CVE-2023-35339
7.5

This vulnerability in Windows CryptoAPI allows attackers to cause a denial of service (DoS) by sending specially crafted requests that crash the servi...

Jul 11, 2023
CVE-2023-35921
7.5

This vulnerability affects multiple SIMATIC MV500 series industrial cameras. An unauthenticated remote attacker can send specially crafted Ethernet fr...

Jul 11, 2023
CVE-2023-3398
7.5

This CVE describes a Denial of Service vulnerability in the draw.io diagramming software. Attackers can cause the application to crash or become unres...

Jun 26, 2023
CVE-2023-33141
7.5

CVE-2023-33141 is a denial-of-service vulnerability in Microsoft's Yet Another Reverse Proxy (YARP) that allows attackers to cause service disruption ...

Jun 23, 2023
CVE-2022-33168
7.5

This vulnerability in IBM Security Directory Suite VA 8.0.1 allows attackers to cause denial of service through uncontrolled resource consumption. Att...

Jun 15, 2023
CVE-2023-2778
7.5

A denial-of-service vulnerability in Rockwell Automation FactoryTalk Transaction Manager allows attackers to crash the application or cause high resou...

Jun 13, 2023
CVE-2023-20883
7.5

This vulnerability in Spring Boot allows denial-of-service attacks when Spring MVC applications are deployed behind reverse proxy caches. Attackers ca...

May 26, 2023
CVE-2023-32067
7.5

CVE-2023-32067 is a denial-of-service vulnerability in the c-ares asynchronous DNS resolver library where an attacker can send a forged UDP packet wit...

May 25, 2023
CVE-2023-2798
7.5

HtmlUnit versions before 2.70.0 contain a stack overflow vulnerability when processing untrusted web content, allowing denial of service attacks. This...

May 25, 2023
CVE-2023-33297
7.5

This vulnerability in Bitcoin Core allows attackers to cause denial of service through inefficient draining of the inventory-to-send queue, leading to...

May 22, 2023
CVE-2023-2295
7.5

This vulnerability in libreswan's IKEv1 Aggressive Mode implementation causes the pluto daemon to crash when receiving specially crafted packets. It a...

May 17, 2023
CVE-2023-32787
7.5

This vulnerability in the OPC UA Legacy Java Stack allows attackers to cause denial-of-service by consuming server resources, making OPC UA servers un...

May 15, 2023
CVE-2023-28356
7.5

This vulnerability allows attackers to send specially crafted messages containing specific character chains that cause a chat service process to enter...

May 11, 2023
CVE-2023-28882
7.5

This vulnerability in Trustwave ModSecurity allows attackers to cause a denial of service by triggering a segmentation fault in the Transaction class,...

Apr 28, 2023
CVE-2023-30798
7.5

This vulnerability in Starlette's MultipartParser allows remote attackers to cause denial of service by sending excessive multipart form data, leading...

Apr 21, 2023
CVE-2022-24035
7.5

A vulnerability in ONOS 2.5.1's intent framework causes purge-requested intents to remain active but unresponsive to topology changes like link failur...

Apr 20, 2023
CVE-2023-21996
7.5

This vulnerability in Oracle WebLogic Server allows unauthenticated attackers to cause a denial of service (DoS) by crashing or hanging the server via...

Apr 18, 2023
CVE-2023-21964
7.5

This vulnerability in Oracle WebLogic Server allows unauthenticated attackers with network access via the T3 protocol to cause a denial of service by ...

Apr 18, 2023
CVE-2022-40946
7.5

This vulnerability allows unauthenticated attackers to cause a denial of service on D-Link DIR-819 routers by sending a specially crafted request to t...

Apr 16, 2023
CVE-2021-39295
7.5

CVE-2021-39295 is a denial-of-service vulnerability in OpenBMC 2.9 where specially crafted IPMI messages sent to the netipmid interface can crash the ...

Apr 15, 2023
CVE-2023-29013
7.5

A memory allocation vulnerability in Go's HTTP header parsing affects Traefik reverse proxy. Attackers can send specially crafted HTTP headers to caus...

Apr 14, 2023
CVE-2023-27643
7.5

A denial-of-service vulnerability in Poweramp music player allows remote attackers to crash the application by triggering specific UI actions. This af...

Apr 14, 2023
CVE-2023-24545
7.5

This vulnerability in Arista CloudEOS allows attackers to cause denial of service by sending malformed packets that leak packet buffers. If enough mal...

Apr 12, 2023
CVE-2023-24860
7.5

CVE-2023-24860 is a denial-of-service vulnerability in Microsoft Defender that allows attackers to crash the antimalware service, temporarily disablin...

Apr 11, 2023
CVE-2023-27191
7.5

This vulnerability in DUALSPACE Super Security v2.3.7 allows attackers to cause denial of service by manipulating SharedPreference files. It affects A...

Apr 11, 2023
CVE-2023-28342
7.5

This vulnerability in Zoho ManageEngine ADSelfService Plus allows unauthenticated attackers to cause denial-of-service via the Mobile App Authenticati...

Apr 5, 2023
CVE-2023-1580
7.5

This vulnerability allows attackers to cause denial of service by exploiting uncontrolled resource consumption in Devolutions Gateway's logging featur...

Apr 2, 2023
CVE-2023-21061
7.5

CVE-2023-21061 is a resource exhaustion vulnerability in the Android kernel that could allow attackers to cause denial of service conditions. This aff...

Mar 24, 2023
CVE-2023-27530
7.5

This CVE describes a denial-of-service vulnerability in Rack's multipart MIME parsing code. Attackers can craft malicious requests that cause excessiv...

Mar 10, 2023
CVE-2022-41333
7.5

An unauthenticated attacker can send crafted GET requests to FortiRecorder's login authentication mechanism, causing uncontrolled resource consumption...

Mar 7, 2023
CVE-2023-27567
7.5

A kernel crash vulnerability in OpenBSD 7.2 occurs when a TCP packet with destination port 0 matches a pf divert-to rule, causing a denial of service....

Mar 3, 2023
CVE-2022-38734
7.5

CVE-2022-38734 is a Denial of Service vulnerability in NetApp StorageGRID's Local Distribution Router service. Attackers can crash the LDR service by ...

Mar 2, 2023
CVE-2023-26104
7.5

All versions of the lite-web-server package are vulnerable to Denial of Service (DoS) when attackers send HTTP requests containing control characters ...

Feb 25, 2023
CVE-2022-40513
7.5

This vulnerability in Qualcomm WLAN firmware allows an attacker to cause a denial-of-service (DoS) condition by exploiting uncontrolled resource consu...

Feb 12, 2023
CVE-2022-44566
7.5

This CVE describes a denial of service vulnerability in ActiveRecord's PostgreSQL adapter where providing integer values outside the 64-bit signed ran...

Feb 9, 2023
CVE-2022-44571
7.5

CVE-2022-44571 is a denial of service vulnerability in Rack's Content-Disposition header parser that allows attackers to craft malicious inputs causin...

Feb 9, 2023
CVE-2023-22792
7.5

This CVE describes a ReDoS (Regular Expression Denial of Service) vulnerability in Ruby on Rails Action Dispatch. Attackers can cause excessive CPU an...

Feb 9, 2023
CVE-2023-22795
7.5

This CVE describes a ReDoS (Regular Expression Denial of Service) vulnerability in Ruby on Rails Action Dispatch. Attackers can send specially crafted...

Feb 9, 2023
CVE-2023-22799
7.5

This CVE describes a Regular Expression Denial of Service (ReDoS) vulnerability in GlobalID versions before 1.0.1. An attacker can cause excessive CPU...

Feb 9, 2023
CVE-2023-25151
7.5

This vulnerability in OpenTelemetry Go instrumentation allows attackers to cause denial-of-service through memory exhaustion. By sending HTTP requests...

Feb 8, 2023
CVE-2023-24574
7.5

This vulnerability in Dell Enterprise SONiC OS allows unauthenticated remote attackers to cause denial of service by exploiting an uncontrolled resour...

Feb 2, 2023
CVE-2023-22664
7.5

This vulnerability affects F5 BIG-IP systems with specific HTTP/2 configurations enabled. When HTTP/2 client-side profile and HTTP MRF Router are both...

Feb 1, 2023
CVE-2022-24294
7.5

CVE-2022-24294 is a regular expression denial-of-service (ReDoS) vulnerability in Apache MXNet that allows attackers to cause excessive CPU consumptio...

Jul 24, 2022
CVE-2020-21405
7.5

This vulnerability in H96 Smart TV Box H96 Pro Plus allows attackers to corrupt files by exploiting the saveDeepColorAttr service. Attackers can poten...

Jul 20, 2022
CVE-2022-30792
7.5

CVE-2022-30792 is a denial-of-service vulnerability in CODESYS V3's CmpChannelServer component that allows unauthorized attackers to consume resources...

Jul 11, 2022
CVE-2022-30591
7.5

CVE-2022-30591 is a denial-of-service vulnerability in quic-go where attackers can cause high CPU consumption by sending incomplete QUIC or HTTP/3 req...

Jul 6, 2022
CVE-2022-26477
7.5

CVE-2022-26477 is a resource exhaustion vulnerability in Apache SystemDS where an attacker can manipulate serialization data to cause CPU exhaustion t...

Jun 27, 2022
CVE-2022-29864
7.5

CVE-2022-29864 is a denial-of-service vulnerability in the OPC UA .NET Standard Stack where an attacker can crash servers by sending a large volume of...

Jun 16, 2022
CVE-2022-29225
7.5

Envoy proxy versions before 1.22.1 have a decompression vulnerability where attackers can send small, highly compressed payloads that expand to consum...

Jun 9, 2022

About Resource Exhaustion (CWE-400)

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, leading to exhaustion.

Our database tracks 695 CVEs classified as CWE-400, with 21 rated critical and 455 rated high severity. The average CVSS score for Resource Exhaustion vulnerabilities is 7.0.

External reference: View CWE-400 on MITRE CWE →

Monitor Resource Exhaustion Vulnerabilities

Get alerted when new Resource Exhaustion CVEs affect your infrastructure.

Start Monitoring Free