Uncontrolled Resource Consumption (CWE-400)
CWE-400 is a Class for products that do not properly control the allocation and maintenance of a limited resource. It is meant for cases where the product is expected to track and limit its own consumption. MITRE discourages mapping to it because it is often confused with the resource exhaustion impact.
About CWE-400
The most common result is denial of service, slowing or crashing the product and possibly its host. In some cases exhaustion forces the product to fail open and weakens its security functions.
MITRE marks CWE-400 as DISCOURAGED for mapping real-world vulnerabilities; analyze the specific mistake that causes resource consumption.
Mitigations
- +Design throttling into the architecture and limit what unauthorized users can make the system spend.
- +Track request rates per user and block requests that exceed a defined threshold.
- +Place specific limits of scale on protocols.
- +Ensure every resource allocation failure places the system in a safe posture.
Detection
Automated dynamic analysis has moderate effectiveness, for example by generating many requests in a short time. Static analysis is limited except for system resources such as files, sockets and processes.
CWE-400 Vulnerabilities
6 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2026-28318 | SolarWinds Serv-U Unauthenticated Denial of Service Vulnerability | SolarWinds | 7.5 | 1.9% | KEV | 2026-06-04 |
| CVE-2026-45498 | Microsoft Defender Denial of Service Vulnerability | Microsoft | 4.0 | 1.3% | KEV | 2026-05-20 |
| CVE-2021-44228 | Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints | Apache Software Foundation | 10.0 | 100.0% | KEV | 2021-12-10 |
| CVE-2020-3566 | Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability | Cisco | 8.6 | 3.7% | KEV | 2020-08-29 |
| CVE-2020-3569 | Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerabilities | Cisco | 8.6 | 3.3% | KEV | 2020-09-23 |
| CVE-2026-0599 | Unbounded External Image Fetch in Validation Leads to Resource-Exhaustion DoS in huggingface/text-generation-inference | huggingface | 7.5 | 29.9% | 2026-02-02 |
Most Affected Vendors
Tool Categories That Address This Weakness
Frequently Asked Questions
What is CWE-400?→
CWE-400 is uncontrolled resource consumption: the product does not limit how much of a finite resource it allocates or keeps.
Should every denial of service bug be mapped to CWE-400?→
MITRE says no. The specific mistake causing the consumption should be mapped instead, since resource exhaustion is often only the impact.
How many exploited vulnerabilities are classified as CWE-400?→
This database lists 6 CVE records mapped to CWE-400 by their CVE Numbering Authority. 5 of them are in the CISA Known Exploited Vulnerabilities catalog, and CISA links 1 to known ransomware campaigns. Examples include CVE-2026-28318, CVE-2026-45498, CVE-2021-44228.
Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.