CWE-400: Resource Exhaustion

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, leading to exhaustion.

695
Total CVEs
21
Critical
455
High
7.0
Avg CVSS

Yearly Trend

2026
73
2025
268
2024
171
2023
96
2022
32

Top Affected Vendors

1 Oracle 50
2 Microsoft 49
3 Apple 25
4 Fedoraproject 19
5 Linux 18
6 Google 17
7 Debian 16
8 Netapp 13
9 Apache 12
10 Juniper 11

All Resource Exhaustion CVEs (695)

CVE-2022-1708
7.5

This vulnerability in CRI-O allows attackers with Kube API access to cause memory or disk space exhaustion on Kubernetes nodes by executing commands t...

Jun 7, 2022
CVE-2022-31028
7.5

MinIO object storage systems are vulnerable to a denial-of-service attack where HTTP clients can establish connections that never close, causing unend...

Jun 7, 2022
CVE-2022-31018
7.5

A denial-of-service vulnerability in Play Framework's forms library allows attackers to crash applications by sending deeply-nested JSON objects. This...

Jun 2, 2022
CVE-2022-26372
7.5

This vulnerability in F5 BIG-IP DNS listeners allows attackers to send specially crafted DNS requests that cause excessive memory consumption, potenti...

May 5, 2022
CVE-2022-22275
7.5

This vulnerability in SonicWall firewalls allows attackers to bypass security policies by sending TCP traffic through HTTP/S channels from WAN to DMZ ...

Apr 27, 2022
CVE-2022-24863
7.5

CVE-2022-24863 is a denial-of-service vulnerability in http-swagger where improper HTTP method handling allows attackers to exhaust system memory. Thi...

Apr 18, 2022
CVE-2022-21155
7.5

CVE-2022-21155 is a denial-of-service vulnerability in Fernhill SCADA Server where a specially crafted network packet can cause the server process to ...

Apr 12, 2022
CVE-2022-24836
7.5

Nokogiri versions before 1.13.4 contain an inefficient regular expression that causes excessive backtracking when detecting encoding in HTML documents...

Apr 11, 2022
CVE-2022-24726
7.5

CVE-2022-24726 is a denial-of-service vulnerability in Istio's control plane (istiod) where a specially crafted message to the validating webhook endp...

Mar 10, 2022
CVE-2022-24713
7.5

CVE-2022-24713 is a vulnerability in the Rust regex crate where built-in mitigations against regex-based denial of service attacks can be bypassed. Th...

Mar 8, 2022
CVE-2022-24678
7.5

This vulnerability allows attackers to flood temporary log locations in Trend Micro security agents, consuming all disk space and causing denial-of-se...

Feb 24, 2022
CVE-2022-21698
7.5

CVE-2022-21698 is a denial-of-service vulnerability in Prometheus client_golang's promhttp package where HTTP servers using certain instrumentation mi...

Feb 15, 2022
CVE-2022-22543
7.5

CVE-2022-22543 is a denial-of-service vulnerability in SAP NetWeaver ABAP Kernel where insufficient validation of SAP-Passport information allows unau...

Feb 9, 2022
CVE-2022-23591
7.5

This CVE describes a stack overflow vulnerability in TensorFlow's GraphDef format that occurs when loading a SavedModel containing self-recursive func...

Feb 4, 2022
CVE-2022-22724
7.5

This vulnerability allows attackers to cause denial of service on Schneider Electric Modicon M340 PLCs by flooding open TCP ports with RST or FIN pack...

Feb 4, 2022
CVE-2021-40406
7.5

A denial of service vulnerability in Reolink RLC-410W cameras allows attackers to prevent legitimate users from logging in by sending specially-crafte...

Jan 28, 2022
CVE-2022-23015
7.5

This vulnerability in F5 BIG-IP systems causes memory exhaustion when specific SSL configurations are enabled. Attackers can trigger resource consumpt...

Jan 25, 2022
CVE-2022-23024
7.5

This vulnerability in F5 BIG-IP AFM's IPsec ALG logging profile causes the Traffic Management Microkernel (TMM) to terminate when processing specific ...

Jan 25, 2022
CVE-2022-22161
7.5

This vulnerability allows unauthenticated attackers to cause a denial of service by flooding traffic to the out-of-band management ethernet port on Ju...

Jan 19, 2022
CVE-2022-21680
7.5

CVE-2022-21680 is a regular expression denial of service (ReDoS) vulnerability in the marked JavaScript markdown parser. Attackers can craft malicious...

Jan 14, 2022
CVE-2021-46149
7.5

This vulnerability allows attackers to cause denial of service by searching for extremely long language names in MediaWiki's Language Name Search feat...

Jan 10, 2022
CVE-2021-43854
7.5

CVE-2021-43854 is a regular expression denial of service (ReDoS) vulnerability in NLTK's tokenization functions. Attackers can craft malicious input t...

Dec 23, 2021
CVE-2021-41014
7.5

CVE-2021-41014 is a denial-of-service vulnerability in Fortinet FortiWeb web application firewalls where unauthenticated attackers can send specially ...

Dec 8, 2021
CVE-2021-37061
7.5

This vulnerability allows attackers to cause denial of service in Huawei smartphones by exploiting uncontrolled resource consumption in the screen pro...

Dec 7, 2021
CVE-2021-22955
7.5

An unauthenticated denial of service vulnerability in Citrix ADC (formerly NetScaler) allows attackers to temporarily disrupt the Management GUI, Nitr...

Dec 7, 2021
CVE-2021-22965
7.5

An unauthenticated administrator can cause denial of service on Pulse Connect Secure devices by sending malformed requests. This affects Pulse Connect...

Nov 19, 2021
CVE-2021-41167
7.5

CVE-2021-41167 is a concurrency control vulnerability in the modern-async JavaScript library where forEachSeries and forEachLimit functions fail to li...

Oct 20, 2021
CVE-2021-31368
7.5

This vulnerability allows unauthenticated attackers to cause a denial of service by flooding traffic to the out-of-band management ethernet port on af...

Oct 19, 2021
CVE-2021-37136
7.5

CVE-2021-37136 is a denial-of-service vulnerability in Netty's Bzip2Decoder that allows attackers to trigger out-of-memory errors by sending specially...

Oct 19, 2021
CVE-2021-41546
7.5

This vulnerability affects Siemens RUGGEDCOM ROX industrial network devices, allowing attackers to cause permanent denial-of-service by exploiting imp...

Oct 12, 2021
CVE-2021-22010
7.5

This vulnerability in VMware vCenter Server allows attackers with network access to port 443 to trigger excessive memory consumption in the VPXD servi...

Sep 23, 2021
CVE-2021-32838
7.5

Flask-RESTX versions before 0.5.1 contain a vulnerable regular expression for email validation that can be exploited for Regular Expression Denial of ...

Sep 20, 2021
CVE-2021-32839
7.5

CVE-2021-32839 is a regular expression denial of service (ReDoS) vulnerability in sqlparse, a Python SQL parser library. The vulnerability allows atta...

Sep 20, 2021
CVE-2020-9000
7.5

This vulnerability in iPortalis iCS allows attackers to trigger repeated .NET Input Validation errors through crafted requests, causing log file growt...

Sep 1, 2021
CVE-2021-33580
7.5

This CVE describes a Regular Expression Denial of Service (ReDoS) vulnerability in Apache Roller where user-controlled inputs (Referer header, request...

Aug 18, 2021
CVE-2021-25659
7.5

A denial-of-service vulnerability in Siemens Automation License Manager allows attackers to crash the service by sending specially crafted packets to ...

Aug 10, 2021
CVE-2021-36716
7.5

CVE-2021-36716 is a regular expression denial of service (ReDoS) vulnerability in the Segment is-email npm package for Node.js. Attackers can cause ex...

Jul 14, 2021
CVE-2021-22119
7.5

Spring Security OAuth 2.0 clients are vulnerable to denial-of-service attacks where attackers can exhaust system resources by repeatedly initiating au...

Jun 29, 2021
CVE-2021-34549
7.5

This vulnerability in Tor allows an attacker to manipulate circuit ID hashing, potentially causing algorithm inefficiency that could degrade performan...

Jun 29, 2021
CVE-2021-30468
7.5

A denial-of-service vulnerability in Apache CXF's JsonMapObjectReaderWriter allows attackers to send specially crafted JSON payloads to web services, ...

Jun 16, 2021
CVE-2021-22904
7.5

This vulnerability in Ruby on Rails' Actionpack gem allows attackers to cause denial of service through token authentication. A too-permissive regular...

Jun 11, 2021
CVE-2021-20591
7.5

This vulnerability allows remote unauthenticated attackers to cause denial of service (DoS) on Mitsubishi Electric MELSEC iQ-R series CPU modules by e...

Jun 11, 2021
CVE-2020-14326
7.5

CVE-2020-14326 is a denial-of-service vulnerability in RESTEasy's RootNode caching mechanism that allows attackers to cause hash flooding, resulting i...

Jun 2, 2021
CVE-2021-33623
7.5

This vulnerability in the trim-newlines Node.js package allows attackers to cause a denial-of-service (DoS) condition through a regular expression den...

May 28, 2021
CVE-2021-32918
7.5

This vulnerability in Prosody XMPP servers allows remote attackers to cause denial-of-service via memory exhaustion without authentication. It affects...

May 13, 2021
CVE-2020-25242
7.5

A vulnerability in Siemens SIMATIC NET CP 343-1 communication processors allows remote attackers to cause a Denial-of-Service condition by sending spe...

May 12, 2021
CVE-2021-31409
7.5

CVE-2021-31409 is a denial-of-service vulnerability in Vaadin's EmailValidator component where unsafe regular expression validation allows attackers t...

May 6, 2021
CVE-2020-28944
7.5

This vulnerability in OX Guard allows attackers to cause Denial of Service by exploiting a WKS server that responds slowly or with excessive data. It ...

Apr 30, 2021
CVE-2020-36320
7.5

This vulnerability allows attackers to cause denial of service through resource exhaustion by submitting specially crafted email addresses that trigge...

Apr 23, 2021
CVE-2021-31405
7.5

This vulnerability allows attackers to cause denial of service (DoS) by submitting specially crafted email addresses that trigger inefficient regular ...

Apr 23, 2021

About Resource Exhaustion (CWE-400)

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, leading to exhaustion.

Our database tracks 695 CVEs classified as CWE-400, with 21 rated critical and 455 rated high severity. The average CVSS score for Resource Exhaustion vulnerabilities is 7.0.

External reference: View CWE-400 on MITRE CWE →

Monitor Resource Exhaustion Vulnerabilities

Get alerted when new Resource Exhaustion CVEs affect your infrastructure.

Start Monitoring Free