Weaknesses of type CWE-400

3,026 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2020-11937MEDIUMResource exhaustion vulnerability in whoopsieEPSS 0.5%CVE-2026-28789HIGHOliveTin: Unauthenticated DoS via concurrent map writes in OAuth2 state handlingEPSS 0.5%CVE-2024-45420MEDIUMZoom Apps - Uncontrolled Resource ConsumptionEPSS 0.5%CVE-2025-52293HIGHA segmentation violaton in the gf_hevc_read_sps_bs_internal function (media_tools/av_parsers.c) of GPAC MP4Box v2.4 allows attackers to causEPSS 0.5%CVE-2024-3872LOWMattermost Mobile app versions 2.13.0 and earlier use a regular expression with polynomial complexity to parse certain deeplinks, which alloEPSS 0.5%CVE-2026-31935HIGHSuricata http2: unbounded resource consumptionEPSS 0.5%CVE-2024-25615MEDIUM An unauthenticated Denial-of-Service (DoS) vulnerability exists in the Spectrum service accessed via the PAPI protocol in ArubaOS 8.x. SuccEPSS 0.5%CVE-2026-48593MEDIUMUnbounded range expansion in cron describe causes memory exhaustion in oban_webEPSS 0.5%CVE-2026-76821HIGHOpenCTI: User-Controlled ReDoS in JSON Ingestion MapperEPSS 0.5%CVE-2020-8229—A memory leak in the OCUtil.dll library used by Nextcloud Desktop Client 2.6.4 can lead to a DoS against the host system.EPSS 0.5%CVE-2026-71486MEDIUMvLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output boundsEPSS 0.5%CVE-2026-0992LOWLibxml2: libxml2: denial of service via crafted xml catalogsEPSS 0.5%CVE-2021-4465HIGHReQuest Serious Play F3 Media Server <= 7.0.3 Remote DoSEPSS 0.5%CVE-2024-35185MEDIUMDenial of service of Minder Server with attacker-controlled REST endpointEPSS 0.5%CVE-2024-33382MEDIUMAn issue in Open5GS v.2.7.0 allows an attacker to cause a denial of service via the 64 unsuccessful UE/gnb registrationEPSS 0.5%CVE-2024-5423MEDIUMUncontrolled Resource Consumption in GitLabEPSS 0.5%CVE-2024-8041MEDIUMUncontrolled Resource Consumption in GitLabEPSS 0.5%CVE-2023-43786MEDIUMLibx11: stack exhaustion from infinite recursion in putsubimage()EPSS 0.5%CVE-2025-21548MEDIUMVulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python). Supported versions that are affected are 9.1.0EPSS 0.5%CVE-2024-43789HIGHDenial of service by the absence of restrictions on replies to posts in DiscourseEPSS 0.5%