CWE-410: Insufficient Resource Pool
The product's resource pool is not large enough to handle peak demand, which allows an attacker to prevent others from accessing the resource by using a (relatively) large number of requests for resources.
Overview
Frequently the consequence is a "flood" of connection or sessions.
Real-world CVEs
19 recorded CVEs are caused by CWE-410 (Insufficient Resource Pool). The highest-severity and most recent are shown first. 2 new CWE-410 CVEs have been recorded so far in 2026 (6 in 2025).