CWE-400 · 3,675 records
Uncontrolled resource consumption
Why does it happen?
Code that parses nested structures sets no depth or size limit. A small input can turn into a disproportionate processing load.
Vulnerable and fixed code
A representative teaching example. Highlighted lines mark where the bug and the fix are.
Vulnerable
function expand(node) { return node.children.map(expand);}Fixed
const MAX_DEPTH = 32;function expand(node, depth = 0) { if (depth > MAX_DEPTH) throw new Error("too deep"); return node.children.map((c) => expand(c, depth + 1));}How to prevent it
- 01Set depth, length and time limits in parsers.
- 02Truncate user input before writing it to logs.
- 03Set alert thresholds for CPU and memory usage.
CVEs in this class
3,677 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
90Now | CVE-2023-44487Weaponized | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, assiemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · CWE-400 | High7.5 | KEV | 100.0% | Oct 10, 2023 |
65This week | CVE-2020-3566Weaponized | Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerabilitycisco · ios xr · CWE-400 | High8.6 | KEV | 3.7% | Aug 29, 2020 |
65This week | CVE-2020-3569Weaponized | Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerabilitiescisco · ios xr · CWE-400 | High8.6 | KEV | 3.3% | Sep 22, 2020 |
64This week | CVE-2023-38180Weaponized | .NET and Visual Studio Denial of Service Vulnerabilitymicrosoft · .net · CWE-400 | High7.5 | KEV | 14.0% | Aug 8, 2023 |
61This week | CVE-2011-3192Weaponized | The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a deniapache · http server · CWE-400 | High7.8 | — | 98.8% | Aug 29, 2011 |
61This week | CVE-2026-28318Weaponized | SolarWinds Serv-U Unauthenticated Denial of Service Vulnerabilitysolarwinds · serv-u · CWE-400 | High7.5 | KEV | 1.9% | Jun 4, 2026 |
60This week | CVE-2026-45498Weaponized | Microsoft Defender Denial of Service Vulnerabilitymicrosoft · defender antimalware platform · CWE-400 | High7.5 | KEV | 1.3% | May 20, 2026 |
58Plan | CVE-2023-45288Proof of concept | HTTP/2 CONTINUATION flood in net/httpgo standard library · net/http · CWE-400 | High7.5 | — | 92.0% | Apr 4, 2024 |
56Plan | CVE-2018-1000115Weaponized | Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDPmemcached · memcached · CWE-400 | High7.5 | — | 88.1% | Mar 5, 2018 |
56Plan | CVE-2019-9515No exploit | Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of serviceapple · swiftnio · CWE-400 | High7.5 | — | 87.4% | Aug 13, 2019 |
55Plan | CVE-2019-9512No exploit | Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of serviceapple · swiftnio · CWE-400 | High7.5 | — | 83.4% | Aug 13, 2019 |
55Plan | CVE-2019-9514No exploit | Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of serviceapple · swiftnio · CWE-400 | High7.5 | — | 82.8% | Aug 13, 2019 |
55Plan | CVE-2023-50868Proof of concept | The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a dennetapp · hci baseboard management controller · CWE-400 | High7.5 | — | 81.7% | Feb 14, 2024 |
54Plan | CVE-2019-9513No exploit | Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of serviceapple · swiftnio · CWE-400 | High7.5 | — | 81.6% | Aug 13, 2019 |
54Plan | CVE-2023-28342No exploit | Zoho ManageEngine ADSelfService Plus before 6218 allows anyone to conduct a Denial-of-Service attack via the Mobile App Authentication API.zohocorp · manageengine adselfservice plus · CWE-400 | High7.5 | — | 78.3% | Apr 5, 2023 |
54Plan | CVE-2004-1464Weaponized | Cisco IOS 12.2(15) and earlier allows remote attackers to cause a denial of service (refused VTY (virtual terminal) connections), via a crafcisco · ios · CWE-400 | Medium5.9 | KEV | 4.8% | Dec 31, 2004 |
53Plan | CVE-2021-21341Proof of concept | XStream can cause a Denial of Servicexstream · xstream · CWE-400 | High7.5 | — | 77.8% | Mar 22, 2021 |
53Plan | CVE-2003-0714Weaponized | The Internet Mail Service in Exchange Server 5.5 and Exchange 2000 allows remote attackers to cause a denial of service (memory exhaustion) microsoft · exchange server · CWE-400 | High7.5 | — | 77.6% | Nov 17, 2003 |
52Plan | CVE-2021-22883No exploit | Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an nodejs · node.js · CWE-400 | High7.5 | — | 74.4% | Mar 3, 2021 |
52Plan | CVE-2018-5390No exploit | Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can linux · linux kernel · CWE-400 | High7.5 | — | 73.7% | Aug 6, 2018 |
52Plan | CVE-2022-29885Proof of concept | EncryptInterceptor does not provide complete protection on insecure networksapache · tomcat · CWE-400 | High7.5 | — | 73.5% | May 12, 2022 |
52Plan | CVE-2019-0199No exploit | The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.14 and 8.5.0 to 8.5.37 accepted streams with excessive numbers of SETTINGS framesapache · tomcat · CWE-400 | High7.5 | — | 72.9% | Apr 10, 2019 |
52Plan | CVE-2017-3144No exploit | Failure to properly clean up closed OMAPI connections can exhaust available socketsisc · dhcp · CWE-400 | High7.5 | — | 72.7% | Jan 16, 2019 |
52Plan | CVE-2018-6389Proof of concept | In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the large list of registwordpress · wordpress · CWE-400 | High7.5 | — | 72.7% | Feb 6, 2018 |
51Plan | CVE-2023-43622Proof of concept | Apache HTTP Server: DoS in HTTP/2 with initial windows size 0apache · http server · CWE-400 | High7.5 | — | 70.6% | Oct 23, 2023 |
- CVE-2023-4448790Now
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as
HighCVSS 7.5KEVWeaponizedEPSS 100%siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmwareOct 10, 2023
- CVE-2020-356665This week
Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability
HighCVSS 8.6KEVWeaponizedEPSS 4%cisco · ios xrAug 29, 2020
- CVE-2020-356965This week
Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerabilities
HighCVSS 8.6KEVWeaponizedEPSS 3%cisco · ios xrSep 22, 2020
- CVE-2023-3818064This week
.NET and Visual Studio Denial of Service Vulnerability
HighCVSS 7.5KEVWeaponizedEPSS 14%microsoft · .netAug 8, 2023
- CVE-2011-319261This week
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a deni
HighCVSS 7.8WeaponizedEPSS 99%apache · http serverAug 29, 2011
- CVE-2026-2831861This week
SolarWinds Serv-U Unauthenticated Denial of Service Vulnerability
HighCVSS 7.5KEVWeaponizedEPSS 2%solarwinds · serv-uJun 4, 2026
- CVE-2026-4549860This week
Microsoft Defender Denial of Service Vulnerability
HighCVSS 7.5KEVWeaponizedEPSS 1%microsoft · defender antimalware platformMay 20, 2026
- CVE-2023-4528858Plan
HTTP/2 CONTINUATION flood in net/http
HighCVSS 7.5Proof of conceptEPSS 92%go standard library · net/httpApr 4, 2024
- CVE-2018-100011556Plan
Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDP
HighCVSS 7.5WeaponizedEPSS 88%memcached · memcachedMar 5, 2018
- CVE-2019-951556Plan
Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service
HighCVSS 7.5No exploitEPSS 87%apple · swiftnioAug 13, 2019
- CVE-2019-951255Plan
Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service
HighCVSS 7.5No exploitEPSS 83%apple · swiftnioAug 13, 2019
- CVE-2019-951455Plan
Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service
HighCVSS 7.5No exploitEPSS 83%apple · swiftnioAug 13, 2019
- CVE-2023-5086855Plan
The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a den
HighCVSS 7.5Proof of conceptEPSS 82%netapp · hci baseboard management controllerFeb 14, 2024
- CVE-2019-951354Plan
Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service
HighCVSS 7.5No exploitEPSS 82%apple · swiftnioAug 13, 2019
- CVE-2023-2834254Plan
Zoho ManageEngine ADSelfService Plus before 6218 allows anyone to conduct a Denial-of-Service attack via the Mobile App Authentication API.
HighCVSS 7.5No exploitEPSS 78%zohocorp · manageengine adselfservice plusApr 5, 2023
- CVE-2004-146454Plan
Cisco IOS 12.2(15) and earlier allows remote attackers to cause a denial of service (refused VTY (virtual terminal) connections), via a craf
MediumCVSS 5.9KEVWeaponizedEPSS 5%cisco · iosDec 31, 2004
- CVE-2021-2134153Plan
XStream can cause a Denial of Service
HighCVSS 7.5Proof of conceptEPSS 78%xstream · xstreamMar 22, 2021
- CVE-2003-071453Plan
The Internet Mail Service in Exchange Server 5.5 and Exchange 2000 allows remote attackers to cause a denial of service (memory exhaustion)
HighCVSS 7.5WeaponizedEPSS 78%microsoft · exchange serverNov 17, 2003
- CVE-2021-2288352Plan
Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an
HighCVSS 7.5No exploitEPSS 74%nodejs · node.jsMar 3, 2021
- CVE-2018-539052Plan
Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can
HighCVSS 7.5No exploitEPSS 74%linux · linux kernelAug 6, 2018
- CVE-2022-2988552Plan
EncryptInterceptor does not provide complete protection on insecure networks
HighCVSS 7.5Proof of conceptEPSS 73%apache · tomcatMay 12, 2022
- CVE-2019-019952Plan
The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.14 and 8.5.0 to 8.5.37 accepted streams with excessive numbers of SETTINGS frames
HighCVSS 7.5No exploitEPSS 73%apache · tomcatApr 10, 2019
- CVE-2017-314452Plan
Failure to properly clean up closed OMAPI connections can exhaust available sockets
HighCVSS 7.5No exploitEPSS 73%isc · dhcpJan 16, 2019
- CVE-2018-638952Plan
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the large list of regist
HighCVSS 7.5Proof of conceptEPSS 73%wordpress · wordpressFeb 6, 2018
- CVE-2023-4362251Plan
Apache HTTP Server: DoS in HTTP/2 with initial windows size 0
HighCVSS 7.5Proof of conceptEPSS 71%apache · http serverOct 23, 2023