Skip to content
Noroxi

CWE-405 · 56 records

Asymmetric Resource Consumption (Amplification)

CVEs in this class

56 records

  • Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes.

    HighCVSS 7.5No exploitEPSS 92%

    linux · linux kernelJun 18, 2019

  • Many records in the additional section cause CPU exhaustion

    HighCVSS 7.5No exploitEPSS 17%

    isc · bind 9Jan 29, 2025

  • Pre-Authentication Memory Exhaustion Denial of Service in MongoDB Server

    HighCVSS 8.7No exploitEPSS 1%

    mongodb inc · mongodb serverFeb 10, 2026

  • Chall-Manager's scenario decoding process does not check for zip bombs

    HighCVSS 8.7No exploitEPSS 0%

    ctfer-io · chall-managerJul 10, 2025

  • CVE-2025-8677
    33Monitor

    Resource exhaustion via malformed DNSKEY handling

    HighCVSS 7.5No exploitEPSS 11%

    isc · bind 9Oct 22, 2025

  • This High severity DoS (Denial of Service) vulnerability was introduced in version 2.0 of Confluence Data Center.

    HighCVSS 8.3No exploitEPSS 1%

    atlassian · confluence data centerOct 21, 2025

  • OCI OpenDDS Secure Amplification

    HighCVSS 7.5No exploitEPSS 2%

    objectcomputing · openddsMay 5, 2022

  • Denial of Service in Page Error Handling

    HighCVSS 7.5No exploitEPSS 2%

    typo3 · typo3Mar 22, 2021

  • Denial of service (DOS) in SAP NetWeaver (remote service for Xcelsius)

    HighCVSS 7.9No exploitEPSS 0%

    sap_se · sap netweaver (remote service for xcelsius)Dec 9, 2025

  • Excessive Memory Use Buffering DTLS Records for a Future Epoch

    HighCVSS 7.5No exploitEPSS 1%

    openssl · opensslAug 25, 2026

  • A vulnerability in the lservnt.exe component of Sentinel License Manager version 8.5.3.35 (fixed in 8.5.3.2403) causes UDP amplification.

    HighCVSS 7.5No exploitEPSS 1%

    gemalto · sentinel license managerAug 17, 2018

  • Envoy vulnerable to HTTP/2 memory exhaustion via cookie header size bypass and HPACK amplification

    HighCVSS 7.5No exploitEPSS 1%

    envoyproxy · envoyJun 17, 2026

  • Mastodon: Exhausting data by an unauthenticated request to the admin retention API

    HighCVSS 7.5No exploitEPSS 1%

    mastodon · mastodonAug 10, 2026

  • body-parser vulnerable to denial of service when url encoding is enabled

    HighCVSS 7.5Proof of conceptEPSS 1%

    openjsf · body-parserSep 10, 2024

  • jwt-go allows excessive memory allocation during header parsing

    HighCVSS 7.5No exploitEPSS 1%

    golang-jwt · jwtMar 21, 2025

  • Suricata oversized resource names utilizing DNS name compression can lead to resource starvation

    HighCVSS 7.5No exploitEPSS 1%

    oisf · suricataJan 6, 2025

  • Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logout

    HighCVSS 7.5No exploitEPSS 1%

    openwebui · open webuiSep 9, 2026

  • devalue vulnerable to denial of service due to memory/CPU exhaustion in devalue.parse

    HighCVSS 7.5No exploitEPSS 1%

    svelte · devalueJan 15, 2026

  • devalue vulnerable to denial of service due to memory exhaustion in devalue.parse

    HighCVSS 7.5No exploitEPSS 1%

    svelte · devalueJan 15, 2026

  • CVE-2023-2992
    30Monitor

    An unauthenticated  denial of service vulnerability exists in the SMM v1, SMM v2, and FPC management web server which can be triggered under

    HighCVSS 7.5No exploitEPSS 1%

    lenovo · nextscale n1200 enclosure firmwareJun 26, 2023

  • IBM MQ Container denial of service

    HighCVSS 7.5No exploitEPSS 1%

    ibm · mq operatorJul 8, 2024

  • Botan Vulnerable to Denial of Service Due to Overly Large Elliptic Curve Parameters

    HighCVSS 7.5No exploitEPSS 1%

    randombit · botanJun 30, 2024

  • Sigstore Timestamp Authority allocates excessive memory during request parsing

    HighCVSS 7.5No exploitEPSS 0%

    linuxfoundation · sigstore timestamp authorityDec 4, 2025

  • CVE-2026-0485
    30Monitor

    Denial of service (DOS) vulnerability in SAP BusinessObjects BI Platform

    HighCVSS 7.5No exploitEPSS 0%

    sap · businessobjects business intelligence platformFeb 10, 2026

  • HCL Connections Docs is vulnerable to a Denial of Service (DoS) attack

    HighCVSS 7.5No exploitEPSS 0%

    hcltech · connections docsAug 14, 2025

All vulnerability classes