Weaknesses of type CWE-400

3,026 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2026-76679HIGHUnauthenticated Denial-of-Service Vulnerabilities in HPE Networking EdgeConnect SD-WAN GatewaysEPSS 0.5%CVE-2026-50879HIGHAn issue in the uploadPostHandler component of Andrei Marcu linx-server v2.3.8 allows attackers to cause a Denial of Service (DoS) via a craEPSS 0.5%CVE-2026-34404MEDIUMNuxt OG Image vulnerable to DoS via image generationEPSS 0.5%CVE-2026-88286HIGHGV-LPC2011/LPC2211 - PTZ Connection-State Accept-Loop Denial of ServiceEPSS 0.5%CVE-2026-75371HIGHAn integer handling flaw in the cobs_decode function of SpaceDot AcubeSAT OBC software commit eaf90ec allows physically-proximate attackers EPSS 0.5%CVE-2026-40988HIGHUnbounded DEFLATE Inflation in SAML 2.0 Service ProviderEPSS 0.5%CVE-2026-88290HIGHGV-LPC2011/LPC2211 - Unauthenticated VLSVR Slowloris and Memory Resource ExhaustionEPSS 0.5%CVE-2026-53539HIGHPython-Multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of serviceEPSS 0.5%CVE-2026-42342HIGHReact Router vulnerable to DoS via unbounded path expansion in __manifest endpointEPSS 0.5%CVE-2026-83280HIGHVulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver-http2). Supported versions that are affectedEPSS 0.5%CVE-2026-59282HIGHSpring Framework Denial of Service via Unbounded List Growth in Data BindingEPSS 0.5%CVE-2026-73773HIGHUnauthenticated Denial-of-Service (DoS) Vulnerability in AOS-CXEPSS 0.5%CVE-2026-70906HIGHVulnerability in Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 25.0.4 and 26.0.2. Easily exploiEPSS 0.5%CVE-2026-41695HIGHDenial of Service in Spring Data Commons Property Path ResolutionEPSS 0.5%CVE-2026-42544HIGHGranian: Unauthenticated DoS via WebSocket subprotocol header panicEPSS 0.5%CVE-2026-41708HIGHSpring Cloud Sleuth instrumentation of Spring TX DoS vulnerabilityEPSS 0.5%CVE-2026-14981HIGHIBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilitiesEPSS 0.5%CVE-2026-83281HIGHVulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver). Supported versions that are affected are 4EPSS 0.5%CVE-2024-25039HIGHIBM Engineering Requirements Management DOORS and DOORS Web Access is affected by multiple vulnerabilitiesEPSS 0.5%CVE-2026-83350HIGHVulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are 21.3-21.23 and 23.4EPSS 0.5%