CWE-405 · 56 records
Asymmetric Resource Consumption (Amplification)
CVEs in this class
56 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
57Plan | CVE-2019-11479No exploit | Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes.linux · linux kernel · CWE-405 | High7.5 | — | 91.7% | Jun 18, 2019 |
35Monitor | CVE-2024-11187No exploit | Many records in the additional section cause CPU exhaustionisc · bind 9 · CWE-405 | High7.5 | — | 16.7% | Jan 29, 2025 |
34Monitor | CVE-2026-25611No exploit | Pre-Authentication Memory Exhaustion Denial of Service in MongoDB Servermongodb inc · mongodb server · CWE-405 | High8.7 | — | 0.6% | Feb 10, 2026 |
34Monitor | CVE-2025-53633No exploit | Chall-Manager's scenario decoding process does not check for zip bombsctfer-io · chall-manager · CWE-405 | High8.7 | — | 0.5% | Jul 10, 2025 |
33Monitor | CVE-2025-8677No exploit | Resource exhaustion via malformed DNSKEY handlingisc · bind 9 · CWE-405 | High7.5 | — | 10.7% | Oct 22, 2025 |
33Monitor | CVE-2025-22166No exploit | This High severity DoS (Denial of Service) vulnerability was introduced in version 2.0 of Confluence Data Center.atlassian · confluence data center · CWE-405 | High8.3 | — | 0.5% | Oct 21, 2025 |
31Monitor | CVE-2021-38447No exploit | OCI OpenDDS Secure Amplificationobjectcomputing · opendds · CWE-405 | High7.5 | — | 2.1% | May 5, 2022 |
31Monitor | CVE-2021-21359No exploit | Denial of Service in Page Error Handlingtypo3 · typo3 · CWE-405 | High7.5 | — | 1.7% | Mar 22, 2021 |
31Monitor | CVE-2025-42874No exploit | Denial of service (DOS) in SAP NetWeaver (remote service for Xcelsius)sap_se · sap netweaver (remote service for xcelsius) · CWE-405 | High7.9 | — | 0.5% | Dec 9, 2025 |
30Monitor | CVE-2026-54874No exploit | Excessive Memory Use Buffering DTLS Records for a Future Epochopenssl · openssl · CWE-405 | High7.5 | — | 1.3% | Aug 25, 2026 |
30Monitor | CVE-2018-15492No exploit | A vulnerability in the lservnt.exe component of Sentinel License Manager version 8.5.3.35 (fixed in 8.5.3.2403) causes UDP amplification.gemalto · sentinel license manager · CWE-405 | High7.5 | — | 1.2% | Aug 17, 2018 |
30Monitor | CVE-2026-47774No exploit | Envoy vulnerable to HTTP/2 memory exhaustion via cookie header size bypass and HPACK amplificationenvoyproxy · envoy · CWE-405 | High7.5 | — | 1.1% | Jun 17, 2026 |
30Monitor | CVE-2026-72914No exploit | Mastodon: Exhausting data by an unauthenticated request to the admin retention APImastodon · mastodon · CWE-405 | High7.5 | — | 0.8% | Aug 10, 2026 |
30Monitor | CVE-2024-45590Proof of concept | body-parser vulnerable to denial of service when url encoding is enabledopenjsf · body-parser · CWE-405 | High7.5 | — | 0.8% | Sep 10, 2024 |
30Monitor | CVE-2025-30204No exploit | jwt-go allows excessive memory allocation during header parsinggolang-jwt · jwt · CWE-405 | High7.5 | — | 0.7% | Mar 21, 2025 |
30Monitor | CVE-2024-55628No exploit | Suricata oversized resource names utilizing DNS name compression can lead to resource starvationoisf · suricata · CWE-405 | High7.5 | — | 0.7% | Jan 6, 2025 |
30Monitor | CVE-2026-87011No exploit | Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logoutopenwebui · open webui · CWE-405 | High7.5 | — | 0.6% | Sep 9, 2026 |
30Monitor | CVE-2026-22775No exploit | devalue vulnerable to denial of service due to memory/CPU exhaustion in devalue.parsesvelte · devalue · CWE-405 | High7.5 | — | 0.6% | Jan 15, 2026 |
30Monitor | CVE-2026-22774No exploit | devalue vulnerable to denial of service due to memory exhaustion in devalue.parsesvelte · devalue · CWE-405 | High7.5 | — | 0.6% | Jan 15, 2026 |
30Monitor | CVE-2023-2992No exploit | An unauthenticated denial of service vulnerability exists in the SMM v1, SMM v2, and FPC management web server which can be triggered underlenovo · nextscale n1200 enclosure firmware · CWE-405 | High7.5 | — | 0.6% | Jun 26, 2023 |
30Monitor | CVE-2024-39743No exploit | IBM MQ Container denial of serviceibm · mq operator · CWE-405 | High7.5 | — | 0.6% | Jul 8, 2024 |
30Monitor | CVE-2024-34703No exploit | Botan Vulnerable to Denial of Service Due to Overly Large Elliptic Curve Parametersrandombit · botan · CWE-405 | High7.5 | — | 0.5% | Jun 30, 2024 |
30Monitor | CVE-2025-66564No exploit | Sigstore Timestamp Authority allocates excessive memory during request parsinglinuxfoundation · sigstore timestamp authority · CWE-405 | High7.5 | — | 0.4% | Dec 4, 2025 |
30Monitor | CVE-2026-0485No exploit | Denial of service (DOS) vulnerability in SAP BusinessObjects BI Platformsap · businessobjects business intelligence platform · CWE-405 | High7.5 | — | 0.4% | Feb 10, 2026 |
30Monitor | CVE-2025-31987No exploit | HCL Connections Docs is vulnerable to a Denial of Service (DoS) attackhcltech · connections docs · CWE-405 | High7.5 | — | 0.2% | Aug 14, 2025 |
- CVE-2019-1147957Plan
Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes.
HighCVSS 7.5No exploitEPSS 92%linux · linux kernelJun 18, 2019
- CVE-2024-1118735Monitor
Many records in the additional section cause CPU exhaustion
HighCVSS 7.5No exploitEPSS 17%isc · bind 9Jan 29, 2025
- CVE-2026-2561134Monitor
Pre-Authentication Memory Exhaustion Denial of Service in MongoDB Server
HighCVSS 8.7No exploitEPSS 1%mongodb inc · mongodb serverFeb 10, 2026
- CVE-2025-5363334Monitor
Chall-Manager's scenario decoding process does not check for zip bombs
HighCVSS 8.7No exploitEPSS 0%ctfer-io · chall-managerJul 10, 2025
- CVE-2025-867733Monitor
Resource exhaustion via malformed DNSKEY handling
HighCVSS 7.5No exploitEPSS 11%isc · bind 9Oct 22, 2025
- CVE-2025-2216633Monitor
This High severity DoS (Denial of Service) vulnerability was introduced in version 2.0 of Confluence Data Center.
HighCVSS 8.3No exploitEPSS 1%atlassian · confluence data centerOct 21, 2025
- CVE-2021-3844731Monitor
OCI OpenDDS Secure Amplification
HighCVSS 7.5No exploitEPSS 2%objectcomputing · openddsMay 5, 2022
- CVE-2021-2135931Monitor
Denial of Service in Page Error Handling
HighCVSS 7.5No exploitEPSS 2%typo3 · typo3Mar 22, 2021
- CVE-2025-4287431Monitor
Denial of service (DOS) in SAP NetWeaver (remote service for Xcelsius)
HighCVSS 7.9No exploitEPSS 0%sap_se · sap netweaver (remote service for xcelsius)Dec 9, 2025
- CVE-2026-5487430Monitor
Excessive Memory Use Buffering DTLS Records for a Future Epoch
HighCVSS 7.5No exploitEPSS 1%openssl · opensslAug 25, 2026
- CVE-2018-1549230Monitor
A vulnerability in the lservnt.exe component of Sentinel License Manager version 8.5.3.35 (fixed in 8.5.3.2403) causes UDP amplification.
HighCVSS 7.5No exploitEPSS 1%gemalto · sentinel license managerAug 17, 2018
- CVE-2026-4777430Monitor
Envoy vulnerable to HTTP/2 memory exhaustion via cookie header size bypass and HPACK amplification
HighCVSS 7.5No exploitEPSS 1%envoyproxy · envoyJun 17, 2026
- CVE-2026-7291430Monitor
Mastodon: Exhausting data by an unauthenticated request to the admin retention API
HighCVSS 7.5No exploitEPSS 1%mastodon · mastodonAug 10, 2026
- CVE-2024-4559030Monitor
body-parser vulnerable to denial of service when url encoding is enabled
HighCVSS 7.5Proof of conceptEPSS 1%openjsf · body-parserSep 10, 2024
- CVE-2025-3020430Monitor
jwt-go allows excessive memory allocation during header parsing
HighCVSS 7.5No exploitEPSS 1%golang-jwt · jwtMar 21, 2025
- CVE-2024-5562830Monitor
Suricata oversized resource names utilizing DNS name compression can lead to resource starvation
HighCVSS 7.5No exploitEPSS 1%oisf · suricataJan 6, 2025
- CVE-2026-8701130Monitor
Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logout
HighCVSS 7.5No exploitEPSS 1%openwebui · open webuiSep 9, 2026
- CVE-2026-2277530Monitor
devalue vulnerable to denial of service due to memory/CPU exhaustion in devalue.parse
HighCVSS 7.5No exploitEPSS 1%svelte · devalueJan 15, 2026
- CVE-2026-2277430Monitor
devalue vulnerable to denial of service due to memory exhaustion in devalue.parse
HighCVSS 7.5No exploitEPSS 1%svelte · devalueJan 15, 2026
- CVE-2023-299230Monitor
An unauthenticated denial of service vulnerability exists in the SMM v1, SMM v2, and FPC management web server which can be triggered under
HighCVSS 7.5No exploitEPSS 1%lenovo · nextscale n1200 enclosure firmwareJun 26, 2023
- CVE-2024-3974330Monitor
IBM MQ Container denial of service
HighCVSS 7.5No exploitEPSS 1%ibm · mq operatorJul 8, 2024
- CVE-2024-3470330Monitor
Botan Vulnerable to Denial of Service Due to Overly Large Elliptic Curve Parameters
HighCVSS 7.5No exploitEPSS 1%randombit · botanJun 30, 2024
- CVE-2025-6656430Monitor
Sigstore Timestamp Authority allocates excessive memory during request parsing
HighCVSS 7.5No exploitEPSS 0%linuxfoundation · sigstore timestamp authorityDec 4, 2025
- CVE-2026-048530Monitor
Denial of service (DOS) vulnerability in SAP BusinessObjects BI Platform
HighCVSS 7.5No exploitEPSS 0%sap · businessobjects business intelligence platformFeb 10, 2026
- CVE-2025-3198730Monitor
HCL Connections Docs is vulnerable to a Denial of Service (DoS) attack
HighCVSS 7.5No exploitEPSS 0%hcltech · connections docsAug 14, 2025