Skip to content
Noroxi

CWE-400 · 3,675 records

Uncontrolled resource consumption

Why does it happen?

Code that parses nested structures sets no depth or size limit. A small input can turn into a disproportionate processing load.

Vulnerable and fixed code

A representative teaching example. Highlighted lines mark where the bug and the fix are.

Vulnerable

ts
function expand(node) {  return node.children.map(expand);}

Fixed

ts
const MAX_DEPTH = 32;function expand(node, depth = 0) {  if (depth > MAX_DEPTH) throw new Error("too deep");  return node.children.map((c) => expand(c, depth + 1));}

How to prevent it

  1. 01Set depth, length and time limits in parsers.
  2. 02Truncate user input before writing it to logs.
  3. 03Set alert thresholds for CPU and memory usage.

CVEs in this class

3,677 records

  • The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as

    HighCVSS 7.5KEVWeaponizedEPSS 100%

    siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmwareOct 10, 2023

  • CVE-2020-3566
    65This week

    Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability

    HighCVSS 8.6KEVWeaponizedEPSS 4%

    cisco · ios xrAug 29, 2020

  • CVE-2020-3569
    65This week

    Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerabilities

    HighCVSS 8.6KEVWeaponizedEPSS 3%

    cisco · ios xrSep 22, 2020

  • CVE-2023-38180
    64This week

    .NET and Visual Studio Denial of Service Vulnerability

    HighCVSS 7.5KEVWeaponizedEPSS 14%

    microsoft · .netAug 8, 2023

  • CVE-2011-3192
    61This week

    The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a deni

    HighCVSS 7.8WeaponizedEPSS 99%

    apache · http serverAug 29, 2011

  • CVE-2026-28318
    61This week

    SolarWinds Serv-U Unauthenticated Denial of Service Vulnerability

    HighCVSS 7.5KEVWeaponizedEPSS 2%

    solarwinds · serv-uJun 4, 2026

  • CVE-2026-45498
    60This week

    Microsoft Defender Denial of Service Vulnerability

    HighCVSS 7.5KEVWeaponizedEPSS 1%

    microsoft · defender antimalware platformMay 20, 2026

  • HTTP/2 CONTINUATION flood in net/http

    HighCVSS 7.5Proof of conceptEPSS 92%

    go standard library · net/httpApr 4, 2024

  • Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDP

    HighCVSS 7.5WeaponizedEPSS 88%

    memcached · memcachedMar 5, 2018

  • Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service

    HighCVSS 7.5No exploitEPSS 87%

    apple · swiftnioAug 13, 2019

  • Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service

    HighCVSS 7.5No exploitEPSS 83%

    apple · swiftnioAug 13, 2019

  • Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service

    HighCVSS 7.5No exploitEPSS 83%

    apple · swiftnioAug 13, 2019

  • The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a den

    HighCVSS 7.5Proof of conceptEPSS 82%

    netapp · hci baseboard management controllerFeb 14, 2024

  • Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service

    HighCVSS 7.5No exploitEPSS 82%

    apple · swiftnioAug 13, 2019

  • Zoho ManageEngine ADSelfService Plus before 6218 allows anyone to conduct a Denial-of-Service attack via the Mobile App Authentication API.

    HighCVSS 7.5No exploitEPSS 78%

    zohocorp · manageengine adselfservice plusApr 5, 2023

  • Cisco IOS 12.2(15) and earlier allows remote attackers to cause a denial of service (refused VTY (virtual terminal) connections), via a craf

    MediumCVSS 5.9KEVWeaponizedEPSS 5%

    cisco · iosDec 31, 2004

  • XStream can cause a Denial of Service

    HighCVSS 7.5Proof of conceptEPSS 78%

    xstream · xstreamMar 22, 2021

  • The Internet Mail Service in Exchange Server 5.5 and Exchange 2000 allows remote attackers to cause a denial of service (memory exhaustion)

    HighCVSS 7.5WeaponizedEPSS 78%

    microsoft · exchange serverNov 17, 2003

  • Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an

    HighCVSS 7.5No exploitEPSS 74%

    nodejs · node.jsMar 3, 2021

  • Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can

    HighCVSS 7.5No exploitEPSS 74%

    linux · linux kernelAug 6, 2018

  • EncryptInterceptor does not provide complete protection on insecure networks

    HighCVSS 7.5Proof of conceptEPSS 73%

    apache · tomcatMay 12, 2022

  • The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.14 and 8.5.0 to 8.5.37 accepted streams with excessive numbers of SETTINGS frames

    HighCVSS 7.5No exploitEPSS 73%

    apache · tomcatApr 10, 2019

  • Failure to properly clean up closed OMAPI connections can exhaust available sockets

    HighCVSS 7.5No exploitEPSS 73%

    isc · dhcpJan 16, 2019

  • In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the large list of regist

    HighCVSS 7.5Proof of conceptEPSS 73%

    wordpress · wordpressFeb 6, 2018

  • Apache HTTP Server: DoS in HTTP/2 with initial windows size 0

    HighCVSS 7.5Proof of conceptEPSS 71%

    apache · http serverOct 23, 2023

All vulnerability classes