The product allows an entity to perform a legitimate but expensive operation before authentication or authorization has taken place.
Volume of CVEs assigned to CWE-408 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-11605HIGH The issue is a resource exhaustion vulnerability associated with DNSSEC validation. BIND always validates all RRSIG records in an answer, even if they are not strictly needed. A qu | Jul 22, 2026 | 7.5 | 35 | NO | NO |
CVE-2026-41405HIGH OpenClaw before 2026.3.31 parses MS Teams webhook request bodies before performing JWT validation, allowing unauthenticated attackers to trigger resource exhaustion. Remote attacke | Apr 28, 2026 | 7.5 | 29 | NO | NO |
CVE-2026-3592MEDIUM BIND resolvers are vulnerable to an amplified resource consumption/exhaustion attack. If a victim resolver makes a query to a specially crafted zone, the resolver will consume dis | May 20, 2026 | 5.3 | 27 | NO | NO |
CVE-2026-41374MEDIUM OpenClaw before 2026.3.31 performs Discord audio preflight transcription before validating member authorization, allowing unauthenticated attackers to consume resources. Remote att | Apr 28, 2026 | 5.3 | 23 | NO | NO |
CVE-2026-41331MEDIUM OpenClaw before 2026.3.31 contains a resource consumption vulnerability in Telegram audio preflight transcription that allows unauthorized group senders to trigger transcription pr | Apr 21, 2026 | 5.3 | 20 | NO | NO |
CVE-2022-2576HIGH In Eclipse Californium version 2.0.0 to 2.7.2 and 3.0.0-3.5.0 a DTLS resumption handshake falls back to a DTLS full handshake on a parameter mismatch without using a HelloVerifyReq | Jul 29, 2022 | 7.5 | 19 | NO | NO |
CVE-2020-1657HIGH On SRX Series devices, a vulnerability in the key-management-daemon (kmd) daemon of Juniper Networks Junos OS allows an attacker to spoof packets targeted to IPSec peers before a s | Oct 16, 2020 | 7.5 | 19 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.