Skip to main content

About CWE-400

The most common result is denial of service, slowing or crashing the product and possibly its host. In some cases exhaustion forces the product to fail open and weakens its security functions.

MITRE marks CWE-400 as DISCOURAGED for mapping real-world vulnerabilities; analyze the specific mistake that causes resource consumption.

MITRE name
Uncontrolled Resource Consumption
Abstraction
Class: a very abstract weakness, typically independent of language or technology
Status
Draft
Also known as
Resource Exhaustion

Mitigations

  • +Design throttling into the architecture and limit what unauthorized users can make the system spend.
  • +Track request rates per user and block requests that exceed a defined threshold.
  • +Place specific limits of scale on protocols.
  • +Ensure every resource allocation failure places the system in a safe posture.

Detection
Automated dynamic analysis has moderate effectiveness, for example by generating many requests in a short time. Static analysis is limited except for system resources such as files, sockets and processes.

CWE-400 Vulnerabilities

6 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2026-28318
SolarWinds Serv-U Unauthenticated Denial of Service Vulnerability
SolarWinds7.51.9%KEV2026-06-04
CVE-2026-45498
Microsoft Defender Denial of Service Vulnerability
Microsoft4.01.3%KEV2026-05-20
CVE-2021-44228
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
Apache Software Foundation10.0100.0%KEV2021-12-10
CVE-2020-3566
Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability
Cisco8.63.7%KEV2020-08-29
CVE-2020-3569
Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerabilities
Cisco8.63.3%KEV2020-09-23
CVE-2026-0599
Unbounded External Image Fetch in Validation Leads to Resource-Exhaustion DoS in huggingface/text-generation-inference
huggingface7.529.9%2026-02-02

Frequently Asked Questions

What is CWE-400?→

CWE-400 is uncontrolled resource consumption: the product does not limit how much of a finite resource it allocates or keeps.

Should every denial of service bug be mapped to CWE-400?→

MITRE says no. The specific mistake causing the consumption should be mapped instead, since resource exhaustion is often only the impact.

How many exploited vulnerabilities are classified as CWE-400?→

This database lists 6 CVE records mapped to CWE-400 by their CVE Numbering Authority. 5 of them are in the CISA Known Exploited Vulnerabilities catalog, and CISA links 1 to known ransomware campaigns. Examples include CVE-2026-28318, CVE-2026-45498, CVE-2021-44228.

Sources

Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.