# CWE-405: Asymmetric Resource Consumption (Amplification)

> As of 2026-10-10, CWE-405 (Amplification) underlies 5 CVEs tracked by Threadlinqs, none of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 5 tracked threats.

**Last updated:** 2026-10-10

## What is CWE-405?

The product does not properly control situations in which an adversary can cause the product to consume or produce excessive resources without requiring the adversary to invest equivalent work or otherwise prove authorization, i.e., the adversary's influence is "asymmetric."

This can lead to poor performance due to "amplification" of resource consumption, typically in a non-linear fashion. This situation is worsened if the product allows malicious users or attackers to consume more resources than their access level permits.

CWE-405 is a class-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Not Language-Specific; Not OS-Specific; Not Architecture-Specific; Not Technology-Specific; Client Server.

_Source: [MITRE CWE](https://cwe.mitre.org/data/definitions/405.html) (CWE-405 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data._

## Consequences

- **Availability** — DoS: Amplification, DoS: Resource Consumption (CPU), DoS: Resource Consumption (Memory), DoS: Resource Consumption (Other). Sometimes this is a factor in "flood" attacks, but other types of amplification exist.

_Source: MITRE CWE, common consequences._

## How CWE-405 is exploited in the wild

Threadlinqs maps 5 CVEs to CWE-405, published between 2026-08-10 and 2026-10-08. None of them is in the CISA KEV catalog yet. By CVSS v3 severity the set splits into 4 high. The highest EPSS score in the set is 0.5% (CVE-2026-104712), the modelled probability of exploitation in the next 30 days. 5 tracked threats reference CWE-405 directly or through a CVE it covers; the most recent is “wolfSSH 1.6.0 patches 5 vulnerabilities incl. critical ECDSA host-key MITM (CVE-2026-16516) and Windows wolfSSHd auth-token reuse (CVE-2026-83540)” (2026-10-08). Affected products concentrate in Go standard library (2), Apache Software Foundation (1), golang.org/x/net (1), among 5 vendors in total.

## Vulnerabilities (CVEs)

All 5 CVEs mapped to CWE-405, CISA KEV first, then by CVSS score.

- [CVE-2026-104712](https://intel.threadlinqs.com/cve/CVE-2026-104712) — CVSS 7.5 high · EPSS 0.5% · published 2026-10-05
- [CVE-2026-72914](https://intel.threadlinqs.com/cve/CVE-2026-72914) — CVSS 7.5 high · EPSS 0.4% · published 2026-08-10
- [CVE-2026-78669](https://intel.threadlinqs.com/cve/CVE-2026-78669) — CVSS 7.5 high · EPSS 0.2% · published 2026-10-08
- [CVE-2026-97031](https://intel.threadlinqs.com/cve/CVE-2026-97031) — CVSS 7.5 high · EPSS 0.1% · published 2026-10-08
- [CVE-2026-84897](https://intel.threadlinqs.com/cve/CVE-2026-84897) — EPSS 0.3% · published 2026-10-07

## Affected vendors

- [Go standard library](https://intel.threadlinqs.com/vendors/go-standard-library) — 2 CVEs
- [Apache Software Foundation](https://intel.threadlinqs.com/vendors/apache-software-foundation) — 1 CVE
- **golang.org/x/net** — 1 CVE
- **mastodon** — 1 CVE
- **wolfSSL Inc.** — 1 CVE

## Threat activity

5 tracked threats cite CWE-405:

- [wolfSSH 1.6.0 patches 5 vulnerabilities incl. critical ECDSA host-key MITM (CVE-2026-16516) and Windows wolfSSHd auth-token reuse (CVE-2026-83540)](https://intel.threadlinqs.com/threat/TL-2026-3044) — CRITICAL · 2026-10-08
- [Apache Struts Vulnerabilities Enable Remote Code Execution and Denial of Service (CVE-2026-104711, CVE-2026-104712, CVE-2026-104713, CVE-2026-104714)](https://intel.threadlinqs.com/threat/TL-2026-2982) — HIGH · 2026-10-06
- [OpenSSL "HollowByte" TLS Handshake Memory-Amplification DoS (No CVE Assigned)](https://intel.threadlinqs.com/threat/TL-2026-1459) — MEDIUM · 2026-07-17
- [BIND 9 Multi-CVE Disclosure (May 2026) — Heap UAF in DoH (CVE-2026-3593), SIG(0) UAF (CVE-2026-5947), Resolver Resend Loop DoS (CVE-2026-5950), CLASS!=IN Assertion DoS (CVE-2026-5946), Glue Amplification (CVE-2026-3592), GSS-API TKEY Memory Exhaustion (CVE-2026-3039)](https://intel.threadlinqs.com/threat/TL-2026-0599) — HIGH · 2026-05-27
- [Unpatched Chromium Background Fetch / Service Worker Persistence Flaw — Silent Post-Close JavaScript Execution (Details Accidentally Leaked by Google)](https://intel.threadlinqs.com/threat/TL-2026-0552) — HIGH · 2026-05-21

## Mitigations

- **Architecture and Design**: An application must make resources available to a client commensurate with the client's access level.
- **Architecture and Design**: An application must, at all times, keep track of allocated resources and meter their usage appropriately.
- **System Configuration**: Consider disabling resource-intensive algorithms on the server side, such as Diffie-Hellman key exchange.

_Source: MITRE CWE, potential mitigations._

## Related weaknesses

- [CWE-400 Uncontrolled Resource Consumption](https://intel.threadlinqs.com/cwe/CWE-400)

Canonical: https://intel.threadlinqs.com/cwe/CWE-405
Source definition: https://cwe.mitre.org/data/definitions/405.html
Detection rules and IOCs for threats exploiting CWE-405 via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
