CWE-408: Incorrect Behavior Order: Early Amplification
The product allows an entity to perform a legitimate but expensive operation before authentication or authorization has taken place.
Last updated
Overview
CWE-408 (Incorrect Behavior Order: Early Amplification) is a base-level software weakness catalogued by MITRE in the Common Weakness Enumeration (CWE). It describes a recurring type of mistake that can lead to exploitable security vulnerabilities.
Real-world CVEs
6 recorded CVEs are caused by CWE-408 (Incorrect Behavior Order: Early Amplification). The highest-severity and most recent are shown first. 4 new CWE-408 CVEs have been recorded so far in 2026.
- CVE-2026-41405
OpenClaw < 2026.3.31 - Resource Exhaustion via Unauthenticated MS Teams Webhook Body Parsing
High · CVSS 8.7 · EPSS 46th2026-04-28 - CVE-2020-1657
Junos OS: SRX Series: An attacker sending spoofed packets to IPSec peers may cause a Denial of Service.
High · CVSS 7.5 · EPSS 60th2020-10-16 - CVE-2026-41374
OpenClaw < 2026.3.31 - Resource Consumption via Discord Audio Preflight Before Member Authorization