Weaknesses of type CWE-400

3,026 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2026-34404MEDIUMNuxt OG Image vulnerable to DoS via image generationEPSS 0.5%CVE-2026-50879HIGHAn issue in the uploadPostHandler component of Andrei Marcu linx-server v2.3.8 allows attackers to cause a Denial of Service (DoS) via a craEPSS 0.5%CVE-2024-37904MEDIUMDenial of service from maliciously configured Git repository in MinderEPSS 0.5%CVE-2026-88286HIGHGV-LPC2011/LPC2211 - PTZ Connection-State Accept-Loop Denial of ServiceEPSS 0.5%CVE-2025-55197MEDIUMpypdf's Manipulated FlateDecode streams can exhaust RAMEPSS 0.5%CVE-2022-48716HIGHASoC: codecs: wcd938x: fix incorrect used of portidEPSS 0.5%CVE-2025-44531HIGHAn issue in Realtek RTL8762EKF-EVB RTL8762E SDK v1.4.0 allows attackers to cause a Denial of Service (DoS) via sending a crafted before a paEPSS 0.5%CVE-2025-70886HIGHAn issue in halo v.2.22.4 and before allows a remote attacker to cause a denial of service via a crafted payload to the public comment submiEPSS 0.5%CVE-2025-62706MEDIUMAuthlib : JWE zip=DEF decompression bomb enables DoSEPSS 0.5%CVE-2024-47239MEDIUMDell PowerScale OneFS versions 8.2.2.x through 9.9.0.0 contain an uncontrolled resource consumption vulnerability. A remote low privileged aEPSS 0.5%CVE-2026-24485HIGHImageMagick: Infinite loop vulnerability when parsing a PCD fileEPSS 0.5%CVE-2024-22164MEDIUMDenial of Service of an Investigation in Splunk Enterprise Security through Investigation attachmentsEPSS 0.5%CVE-2022-32505HIGHAn issue was discovered on certain Nuki Home Solutions devices. It is possible to send multiple BLE malformed packets to block some of the fEPSS 0.5%CVE-2019-15264HIGHCisco Aironet Access Points and Catalyst 9100 Access Points CAPWAP Denial of Service VulnerabilityEPSS 0.5%CVE-2024-39810MEDIUMServer crash via Elasticsearch certificate fileEPSS 0.5%CVE-2026-35406MEDIUMAardvark-dns has incorrect error handling for malformed tcp packetsEPSS 0.5%CVE-2024-33618HIGHUncontrolled Resource Consumption in Bosch VMS Central Server in Bosch VMS 12.0.1 allows attackers to consume excessive amounts of disk spEPSS 0.5%CVE-2026-76700MEDIUMUnauthenticated Denial-of-Service Vulnerabilities in HPE Networking EdgeConnect SD-WAN GatewaysEPSS 0.5%CVE-2024-53851MEDIUMPartial denial of service via inline oneboxes in DiscourseEPSS 0.5%CVE-2026-6797MEDIUMSanluan PublicCMS DocToHtmlUtils.java ZipSecureFile.setMinflateRatio resource consumptionEPSS 0.5%