What is CWE-400?
MITRE CWEThe product does not properly control the allocation and maintenance of a limited resource.
Verify to analyze this CWE entry
A short verification protects the official data source and prevents automated AI abuse.
The product does not properly control the allocation and maintenance of a limited resource.
A short verification protects the official data source and prevents automated AI abuse.
The product does not properly control the allocation and maintenance of a limited resource.
Availability
DoS: Crash, Exit, or Restart, DoS: Resource Consumption (CPU), DoS: Resource Consumption (Memory), DoS: Resource Consumption (Other)
If an attacker can trigger the allocation of the limited resources, but the number or size of the resources is not controlled, then the most common result is denial of service. This would prevent valid users from accessing the product, and it could potentially have an impact on the surrounding environment, i.e., the product may slow down, crash due to unhandled errors, or lock out legitimate users. For example, a memory exhaustion attack against an application could slow down the application as well as its host operating system.
Access Control, Other
Bypass Protection Mechanism, Other
In some cases it may be possible to force the product to "fail open" in the event of resource exhaustion. The state of the product -- and possibly the security functionality - may then be compromised.
These examples illustrate this CWE entry and are not an exhaustive list of related vulnerabilities.
CWE™ Program, operated by The MITRE Corporation. Copyright © 2006–2026, The MITRE Corporation. The MITRE Corporation hereby grants you a non-exclusive, royalty-free license to use CWE for research, development, and commercial purposes. CWE Terms of Use.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan
en