CWE-410Class

Insufficient Resource Pool

Incomplete in the CWE catalog · 21 CVEs mapped

21
CVEs mapped
6.0
Median CVSS
What it is

The product's resource pool is not large enough to handle peak demand, which allows an attacker to prevent others from accessing the resource by using a (relatively) large number of requests for resources.

Recent examples
5.3cvss
CVE-2026-58218

Samba: dns signing dos via tkey name cache exhaustion

A flaw was found in Samba's internal DNS server where unauthenticated TKEY registration requests were added to the TKEY name cache before being rejected. A remote, unauthenticated attacker can exploit this behavior by sending a large number of TKEY requests with arbitrary names, exhausting the cache and evicting legitimate TKEY entries. This can prevent legitimate TSIG authentication for signed DNS queries, resulting in a denial of service.

MEDIUMno explanation yet
1%
epss
6.3cvss
CVE-2026-34019

BIG-IP BFD vulnerability

When Bidirectional Forwarding Detection (BFD) is configured in Static and Dynamic routing protocols, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to stop processing BFD packets and cause the configured routing protocol to fail over.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

MEDIUMno explanation yet
0%
epss
3.5cvss
CVE-2025-2134

IBM Jazz Reporting Service Denial of Service

IBM Jazz Reporting Service could allow an authenticated user on the network to affect the system's performance using complicated queries due to insufficient resource pooling.

LOWno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-410
Abstraction
Class
Structure
Simple
Status
Incomplete
References (1)