What is CWE-405?
The product does not properly control situations in which an adversary can cause the product to consume or produce excessive resources without requiring the adversary to invest equivalent work or otherwise prove authorization, i.e., the adversary's influence is "asymmetric."
This can lead to poor performance due to "amplification" of resource consumption, typically in a non-linear fashion. This situation is worsened if the product allows malicious users or attackers to consume more resources than their access level permits.
CWE-405 is a class-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Not Language-Specific; Not OS-Specific; Not Architecture-Specific; Not Technology-Specific; Client Server.
Source: MITRE CWE (CWE-405 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.
Consequences
- Availability — DoS: Amplification, DoS: Resource Consumption (CPU), DoS: Resource Consumption (Memory), DoS: Resource Consumption (Other). Sometimes this is a factor in "flood" attacks, but other types of amplification exist.
Source: MITRE CWE, common consequences.
How CWE-405 is exploited in the wild
Threadlinqs maps 5 CVEs to CWE-405, published between 2026-08-10 and 2026-10-08. None of them is in the CISA KEV catalog yet. By CVSS v3 severity the set splits into 4 high. The highest EPSS score in the set is 0.5% (CVE-2026-104712), the modelled probability of exploitation in the next 30 days. 5 tracked threats reference CWE-405 directly or through a CVE it covers; the most recent is “wolfSSH 1.6.0 patches 5 vulnerabilities incl. critical ECDSA host-key MITM (CVE-2026-16516) and Windows wolfSSHd auth-token reuse (CVE-2026-83540)” (2026-10-08). Affected products concentrate in Go standard library (2), Apache Software Foundation (1), golang.org/x/net (1), among 5 vendors in total.
Vulnerabilities (CVEs)
All 5 CVEs mapped to CWE-405, CISA KEV first, then by CVSS score.
- CVE-2026-104712 — CVSS 7.5 high · EPSS 0.5% · published 2026-10-05
- CVE-2026-72914 — CVSS 7.5 high · EPSS 0.4% · published 2026-08-10
- CVE-2026-78669 — CVSS 7.5 high · EPSS 0.2% · published 2026-10-08
- CVE-2026-97031 — CVSS 7.5 high · EPSS 0.1% · published 2026-10-08
- CVE-2026-84897 — EPSS 0.3% · published 2026-10-07
Affected vendors
- Go standard library — 2 CVEs
- Apache Software Foundation — 1 CVE
- golang.org/x/net — 1 CVE
- mastodon — 1 CVE
- wolfSSL Inc. — 1 CVE
Threat activity
5 tracked threats cite CWE-405:
- wolfSSH 1.6.0 patches 5 vulnerabilities incl. critical ECDSA host-key MITM (CVE-2026-16516) and Windows wolfSSHd auth-token reuse (CVE-2026-83540)CRITICAL
- Apache Struts Vulnerabilities Enable Remote Code Execution and Denial of Service (CVE-2026-104711, CVE-2026-104712, CVE-2026-104713, CVE-2026-104714)HIGH
- OpenSSL "HollowByte" TLS Handshake Memory-Amplification DoS (No CVE Assigned)MEDIUM
- BIND 9 Multi-CVE Disclosure (May 2026) — Heap UAF in DoH (CVE-2026-3593), SIG(0) UAF (CVE-2026-5947), Resolver Resend Loop DoS (CVE-2026-5950), CLASS!=IN Assertion DoS (CVE-2026-5946), Glue Amplification (CVE-2026-3592), GSS-API TKEY Memory Exhaustion (CVE-2026-3039)HIGH
- Unpatched Chromium Background Fetch / Service Worker Persistence Flaw — Silent Post-Close JavaScript Execution (Details Accidentally Leaked by Google)HIGH
Mitigations
- Architecture and Design: An application must make resources available to a client commensurate with the client's access level.
- Architecture and Design: An application must, at all times, keep track of allocated resources and meter their usage appropriately.
- System Configuration: Consider disabling resource-intensive algorithms on the server side, such as Diffie-Hellman key exchange.
Source: MITRE CWE, potential mitigations.