Cyber Resilience

CWE · MITRE source

CWE-400Uncontrolled Resource Consumption

Abstraction: Class · CVEs in our corpus: 3,481

The product does not properly control the allocation and maintenance of a limited resource.

Last updated: 22 August 2026 07:11 UTC

Cumulative inbound coverage

How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.

Collective: partial · 3 mapping(s) from 1 framework(s): CAPEC 3 (partial)

See the full cumulative-coverage rollup →

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • SC-10 Network Disconnect
  • SC-22 Architecture and Provisioning for Name/Address Resolution Service
  • SC-36 Distributed Processing and Storage
  • SC-47 Alternate Communications Paths
Detect
Catch it (CSF Detect / Respond)
  • DE.CM-09
Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)

NIST 800-53 r5 controls that address this weakness (21)AI-assisted

Showing the 15 most specific. Generic controls that address many weakness types are collapsed below.

Control Title Family Why it addresses this CWE
SC-10Network DisconnectSCTerminating idle connections bounds resource consumption that would otherwise allow uncontrolled accumulation of open sessions.
SC-22Architecture and Provisioning for Name/Address Resolution ServiceSCFault tolerance reduces the impact of resource-exhaustion attacks against the organization's name services.
SC-36Distributed Processing and StorageSCSpreading processing and storage across locations prevents a single resource pool from being exhausted by one attack, mitigating uncontrolled consumption.
CP-4Contingency Plan TestingCPContingency plan testing includes resource exhaustion scenarios to verify recovery, making it harder for attackers to sustain exploits that cause uncontrolled consumption.
CP-5Contingency Plan UpdateCPUpdated contingency plans include current procedures to detect, contain, and recover from resource exhaustion, limiting an attacker's ability to sustain impact from uncontrolled consumption.
CP-7Alternate Processing SiteCPAlternate site allows resumption of operations if resource exhaustion at the primary site is exploited to cause unavailability.
SI-13Predictable Failure PreventionSIMTTF monitoring plus ready substitutes directly mitigate sustained resource exhaustion by allowing component swap before or at failure.
SI-4System MonitoringSIMonitors for resource exhaustion and denial-of-service patterns that indicate uncontrolled consumption.
SI-8Spam ProtectionSIBlocking or throttling unsolicited messages at entry/exit points prevents attackers from flooding queues, storage, or processing resources.
SA-11Developer Testing and EvaluationSAResource consumption and denial-of-service testing performed under the assessment plan detects uncontrolled allocation paths that are subsequently fixed.
SA-24Design For Cyber ResiliencySAResiliency techniques such as redundancy, throttling, and adaptive response limit uncontrolled resource consumption and denial-of-service effects.
AC-10Concurrent Session ControlACLimiting concurrent sessions directly prevents uncontrolled resource consumption by capping the number of active sessions per user or account.
AU-6Audit Record Review, Analysis, and ReportingAUAnalysis identifies uncontrolled resource consumption indicative of denial-of-service or abuse attempts.
IR-10Integrated Information Security Analysis TeamIRThe team can analyze and respond to resource exhaustion incidents, reducing the impact of attacks that exploit uncontrolled consumption weaknesses.
MA-6Timely MaintenanceMATimely maintenance support and spare parts enable rapid recovery from failures induced by uncontrolled resource consumption, shortening the impact window of denial-of-service attacks.
Show 6 more broadly-applicable controls
SC-47Alternate Communications PathsSCAlternate paths allow continued C2 operations when an attacker exploits resource-consumption weaknesses against the primary channel.
SC-5Denial-of-service ProtectionSCDirectly limits uncontrolled resource consumption that leads to denial-of-service.
SC-6Resource AvailabilitySCDirectly mitigates uncontrolled consumption by enforcing allocation limits/quotas that preserve availability for legitimate use.
CP-8Telecommunications ServicesCPAlternate telecommunications services enable resumption of essential functions when primary services become unavailable due to uncontrolled resource consumption.
PL-6Security-related Activity PlanningPLPlanning and coordination of security activities (scans, tests, maintenance) directly imposes scheduling and throttling that prevents those activities from producing uncontrolled resource consumption.
PM-6Measures of PerformancePMPerformance metrics and monitoring inherently track resource consumption patterns, making uncontrolled consumption easier to detect and mitigate.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2021-44228 KEV 10.010.01.00002021-12-10
CVE-2020-3566 KEV 8.88.60.03702020-08-29
CVE-2020-3569 KEV 8.88.60.03322020-09-23
CVE-2023-38180 KEV 8.57.50.14022023-08-08
CVE-2023-44487 KEV 8.57.51.00002023-10-10
CVE-2026-28318 KEV 8.57.50.08352026-06-04
CVE-2017-5637 8.47.50.73062017-10-10
CVE-2018-6389 8.47.50.72672018-02-06
CVE-2018-1000115 8.47.50.88112018-03-05
CVE-2018-5390 8.47.50.73722018-08-06
CVE-2017-3144 8.47.50.72722019-01-16
CVE-2019-0199 8.47.50.72862019-04-10
CVE-2019-9512 8.47.50.83432019-08-13
CVE-2019-9513 8.47.50.81562019-08-13
CVE-2019-9514 8.47.50.82812019-08-13
CVE-2019-9515 8.47.50.87402019-08-13
CVE-2019-14901 8.49.80.16912019-11-29
CVE-2021-22883 8.47.50.74352021-03-03
CVE-2021-21341 8.47.50.77802021-03-23
CVE-2022-29885 8.47.50.73472022-05-12
CVE-2023-21547 8.47.50.89282023-01-10
CVE-2023-28342 8.47.50.78342023-04-05
CVE-2023-43622 8.47.50.70592023-10-23
CVE-2023-50868 8.47.50.81732024-02-14
CVE-2019-15226 8.37.50.65392019-10-09