CWE-400— Uncontrolled Resource Consumption (Denial of Service)
The product does not properly control the allocation and maintenance of a limited resource.— MITRE CWE catalog
4,283 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-400page 8 of 86
- CVE-2018-12122HIGHCVSS 7.5EG 7.82018-11-28
Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Slowloris HTTP Denial of Service: An attacker can cause a Denial of Service (DoS) by sending headers very slowly keeping HTTP or HTTPS connections and associated re…
- CVE-2016-8610HIGHCVSS 7.5EG 7.82017-11-13
A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use this flaw to make a …
- CVE-2024-44160HIGHCVSS 5.5EG 7.82024-09-17
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7. Processing a maliciously crafted texture may lead to unexpected app termination.
- CVE-2024-40841HIGHCVSS 5.5EG 7.82024-09-17
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7. Processing a maliciously crafted video file may lead to unexpected app termination.
- CVE-2014-5418HIGHCVSS v2 7.8EG 7.82015-01-17
GE Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware 4.2.1 and earlier and Multilink ML810, ML3000, and ML3100 switches with firmware 5.2.0 and earlier allow remote attackers to cause a denial of service (resource consumpt…
- CVE-2012-6638HIGHCVSS v2 7.8EG 7.82014-02-15
The tcp_rcv_state_process function in net/ipv4/tcp_input.c in the Linux kernel before 3.2.24 allows remote attackers to cause a denial of service (kernel resource consumption) via a flood of SYN+FIN TCP packets, a different vulnerability t…
- CVE-2012-0024HIGHCVSS v2 7.8EG 7.82012-01-08
MaraDNS before 1.3.07.12 and 1.4.x before 1.4.08 computes hash values for DNS data without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by send…
- CVE-2011-3192HIGHCVSS v2 7.8EG 7.82011-08-29
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping r…
- CVE-2010-4686HIGHCVSS v2 7.8EG 7.82011-01-07
CallManager Express (CME) on Cisco IOS before 15.0(1)XA1 does not properly handle SIP TRUNK traffic that contains rate bursts and a "peculiar" request size, which allows remote attackers to cause a denial of service (memory consumption) by…
- CVE-2010-4671HIGHCVSS v2 7.8EG 7.82011-01-07
The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Cisco IOS before 15.0(1)XA5 allows remote attackers to cause a denial of service (CPU consumption and device hang) by sending many Router Advertisement (RA) messages …
- CVE-2008-4077HIGHCVSS v2 7.8EG 7.82008-09-15
The CGI scripts in (1) LedgerSMB (LSMB) before 1.2.15 and (2) SQL-Ledger 2.8.17 and earlier allow remote attackers to cause a denial of service (resource exhaustion) via an HTTP POST request with a large Content-Length.
- CVE-2007-0086HIGHCVSS v2 7.8EG 7.82007-01-05
The Apache HTTP Server, when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (network bandwidth consumption) via a Range header that specifies multiple copies of the same fra…
- CVE-2026-61617HIGHCVSS 7.7EG 7.72026-08-26
Wings is the server control plane for the Pterodactyl game-server management panel. In versions up to and including 1.13.2, the SFTP write path does not enforce a server's disk quota during a transfer, allowing a tenant with SFTP write acc…
- CVE-2026-9165HIGHCVSS 7.7EG 7.72026-07-06
A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Central does not limit the depth of GraphQL queries served on the authenticated GraphQL API. An authenticated user with a valid API token can send deeply nested …
- CVE-2026-13149HIGHCVSS 7.7EG 7.72026-06-30
brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(),…
- CVE-2026-33235HIGHCVSS 7.7EG 7.72026-06-24
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. In versions prior to 0.6.52, the Fill Text Template block is vulnerable to a Denial of Service (DoS) attack. While t…
- CVE-2025-57751HIGHCVSS 7.7EG 7.72025-08-21
pyLoad is the free and open-source Download Manager written in pure Python. The jk parameter is received in pyLoad CNL Blueprint. Due to the lack of jk parameter verification, the jk parameter input by the user is directly determined as dy…
- CVE-2025-46580HIGHCVSS 7.7EG 7.72025-04-27
There is a code-related vulnerability in the GoldenDB database product. Attackers can access system tables to disrupt the normal operation of business SQL.
- CVE-2024-3056HIGHCVSS 7.7EG 7.72024-08-02
A flaw was found in Podman. This issue may allow an attacker to create a specially crafted container that, when configured to share the same IPC with at least one other container, can create a large number of IPC resources in /dev/shm. The…
- CVE-2024-5795HIGHCVSS 7.7EG 7.72024-07-16
A Denial of Service vulnerability was identified in GitHub Enterprise Server that allowed an attacker to cause unbounded resource exhaustion by sending a large payload to the Git server. This vulnerability affected all versions of GitHub E…
- CVE-2023-42358HIGHCVSS 7.7EG 7.72024-01-03
An issue was discovered in O-RAN Software Community ric-plt-e2mgr in the G-Release environment, allows remote attackers to cause a denial of service (DoS) via a crafted request to the E2Manager API component.
- CVE-2022-37973HIGHCVSS 7.7EG 7.72022-10-11
Windows Local Session Manager (LSM) Denial of Service Vulnerability
- CVE-2022-36049HIGHCVSS 7.7EG 7.72022-09-07
Flux2 is a tool for keeping Kubernetes clusters in sync with sources of configuration, and Flux's helm-controller is a Kubernetes operator that allows one to declaratively manage Helm chart releases. Helm controller is tightly integrated w…
- CVE-2022-33142HIGHCVSS 7.7EG 7.72022-08-23
Authenticated (subscriber+) Denial Of Service (DoS) vulnerability in WordPlus WordPress Better Messages plugin <= 1.9.10.57 at WordPress.
- CVE-2022-20808HIGHCVSS 7.7EG 7.72022-07-06
A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to incorrect handling of mult…
- CVE-2022-20692HIGHCVSS 7.7EG 7.72022-04-15
A vulnerability in the NETCONF over SSH feature of Cisco IOS XE Software could allow a low-privileged, authenticated, remote attacker to cause a denial of service condition (DoS) on an affected device. This vulnerability is due to insuffic…
- CVE-2021-39877HIGHCVSS 7.7EG 7.72021-10-04
A vulnerability was discovered in GitLab starting with version 12.2 that allows an attacker to cause uncontrolled resource consumption with a specially crafted file.
- CVE-2021-1623HIGHCVSS 7.7EG 7.72021-09-23
A vulnerability in the Simple Network Management Protocol (SNMP) punt handling function of Cisco cBR-8 Converged Broadband Routers could allow an authenticated, remote attacker to overload a device punt path, resulting in a denial of servi…
- CVE-2021-22181HIGHCVSS 7.7EG 7.72021-06-11
A denial of service vulnerability in GitLab CE/EE affecting all versions since 11.8 allows an attacker to create a recursive pipeline relationship and exhaust resources.
- CVE-2020-15114HIGHCVSS 7.7EG 7.72020-08-06
In etcd before versions 3.3.23 and 3.4.10, the etcd gateway is a simple TCP proxy to allow for basic service discovery and access. However, it is possible to include the gateway address as an endpoint. This results in a denial of service, …
- CVE-2019-1965HIGHCVSS 7.7EG 7.72019-08-28
A vulnerability in the Virtual Shell (VSH) session management for Cisco NX-OS Software could allow an authenticated, remote attacker to cause a VSH process to fail to delete upon termination. This can lead to a build-up of VSH processes th…
- CVE-2018-0309HIGHCVSS 7.7EG 7.72018-06-21
A vulnerability in the implementation of a specific CLI command and the associated Simple Network Management Protocol (SNMP) MIB for Cisco NX-OS (in standalone NX-OS mode) on Cisco Nexus 3000 and 9000 Series Switches could allow an authent…
- CVE-2017-12090HIGHCVSS 7.7EG 7.72018-04-05
An exploitable denial of service vulnerability exists in the processing of snmp-set commands of the Allen Bradley Micrologix 1400 Series B FRN 21.2 and below. A specially crafted snmp-set request, when sent without associated firmware flas…
- CVE-2017-6019HIGHCVSS 7.5EG 7.72017-04-07
An issue was discovered in Schneider Electric Conext ComBox, model 865-1058, all firmware versions prior to V3.03 BN 830. A series of rapid requests to the device may cause it to reboot.
- CVE-2019-9516HIGHCVSS 6.5EG 7.72019-08-13
Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with a 0-length header name and 0-length header value, optionally Huffman encoded into 1-byte o…
- CVE-2026-62518HIGHCVSS 7.6EG 7.62026-07-21
Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacke…
- CVE-2026-23809HIGHCVSS 7.6EG 7.62026-03-04
A technique has been identified that adapts a known port-stealing method to Wi-Fi environments that use multiple BSSIDs. By leveraging the relationship between BSSIDs and their associated virtual ports, an attacker could potentially bypass…
- CVE-2023-26601HIGHCVSS 7.5EG 7.62023-03-06
Zoho ManageEngine ServiceDesk Plus through 14104, Asset Explorer through 6987, ServiceDesk Plus MSP before 14000, and Support Center Plus before 14000 allow Denial-of-Service (DoS).
- CVE-2018-5391HIGHCVSS 7.5EG 7.62018-09-06
The Linux kernel, versions 3.9+, is vulnerable to a denial of service attack with low rates of specially modified packets targeting IP fragment re-assembly. An attacker may cause a denial of service condition by sending specially crafted I…
- CVE-2026-14854HIGHCVSS 7.5EG 7.52026-10-11
The WooCommerce Bookings WordPress plugin before 3.11.0 does not limit a user-supplied value before using it to allocate memory in one of its unauthenticated AJAX actions, allowing unauthenticated attackers to exhaust server memory and cau…
- CVE-2026-107840HIGHCVSS 7.5EG 7.52026-10-09
yopass is a service for securely sharing secrets, passwords, and files. Prior to version 14.7.0, the Prometheus metrics middleware in pkg/server/server.go uses the attacker-controlled r.Method value directly as the method label for yopass_…
- CVE-2026-107839HIGHCVSS 7.5EG 7.52026-10-09
ageLANServer provides a cross-platform web server and launcher for offline multiplayer in several Age of Empires and Age of Mythology games. Prior to version 1.15.2, the AoE3 POST /game/cloud/getFileURL handler in the bundled game server h…
- CVE-2026-107805HIGHCVSS 7.5EG 7.52026-10-09
Nginx UI is a web user interface for the Nginx web server. From 2.5.0 until 2.6.0, the node-signature authentication path performs temporary file staging of an attacker-controlled request body and synchronizes it before validating the body…
- CVE-2026-84276HIGHCVSS 7.5EG 7.52026-10-08
IBM Guardium Data Protection 12.2.2 is affected by a denial-of-service vulnerability in the edge-controller. An unauthenticated remote attacker with network access to the edge-controller gRPC service can provide malformed task data that tr…
- CVE-2026-105830HIGHCVSS 7.5EG 7.52026-10-08
league/commonmark from 2.0.0 before 2.10.2 contains a quadratic-time denial of service vulnerability in the GitHub Flavored Markdown Table extension's TableStartParser::tryStart() block-start scan. Unauthenticated attackers can submit a la…
- CVE-2026-16169HIGHCVSS 7.5EG 7.52026-10-08
IBM DataPower Gateway 11.0.0.0 through 11.0.0.2 could allow a remote attacker to cause a denial of service due to uncontrolled resource consumption.
- CVE-2026-95116HIGHCVSS 7.5EG 7.52026-10-08
An issue in libming through 0.4.8 allows a remote attacker to cause a denial of service via the readtag_file() in src/blocks/fromswf.c.
- CVE-2026-95184HIGHCVSS 7.5EG 7.52026-10-08
Improper certificate validation in gnutls v3.8.13 causes the application to reject legitimate certificates for valid users, leading to a Denial of Service (DoS).
- CVE-2026-95209HIGHCVSS 7.5EG 7.52026-10-08
An issue in gnutls v3.8.13 causes legitimate CA certificates to be rejected, leading to a Denial of Service (DoS).
- CVE-2026-107227HIGHCVSS 7.5EG 7.52026-10-07
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.2.0 until 3.0.14, WebSocket permessage-deflate decompression is unbounded when compression is enab…
Map vulnerabilities like CWE-400 to your infrastructure
EchelonGraph correlates every CVE — across CWE-400 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →