Weaknesses of type CWE-400

3,026 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2026-6797MEDIUMSanluan PublicCMS DocToHtmlUtils.java ZipSecureFile.setMinflateRatio resource consumptionEPSS 0.5%CVE-2020-3543MEDIUMCisco Video Surveillance 8000 Series IP Cameras Cisco Discovery Protocol Memory Leak VulnerabilityEPSS 0.5%CVE-2026-42343MEDIUMFastGPT: Uncontrolled Resource Consumption leading to Sandbox ExhaustionEPSS 0.5%CVE-2025-11635MEDIUMTomofun Furbo 360 File Upload resource consumptionEPSS 0.5%CVE-2026-20066MEDIUMMultiple Cisco Products Snort 3 TBD Denial of Service VulnerabilityEPSS 0.5%CVE-2025-55558HIGHA buffer overflow occurs in pytorch v2.7.0 when a PyTorch model consists of torch.nn.Conv2d, torch.nn.functional.hardshrink, and torch.TensoEPSS 0.5%CVE-2026-86421MEDIUMImageMagick before 7.1.2-30 Memory Leak via MSL decoderEPSS 0.5%CVE-2025-30730HIGHVulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are afEPSS 0.5%CVE-2026-55531MEDIUMPraisonAI: Unauthenticated unbounded session accumulation in the PraisonAI MCP HTTP server (memory exhaustion; session TTL never enforced)EPSS 0.5%CVE-2026-65976MEDIUMDeskflow: Clipboard receiver can accumulate data beyond Deskflow's configured clipboard size limitEPSS 0.5%CVE-2026-45802MEDIUMFPDI: Memory Exhaustion and Endless Loop in FPDI leads to Denial of ServiceEPSS 0.5%CVE-2026-73215HIGHThe coturn server can end in a state where it does not accept more requests with "even-port" enabled.EPSS 0.5%CVE-2026-47052MEDIUMVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: InnoDB). Supported versions that are affected are MySQEPSS 0.4%CVE-2026-61128MEDIUMVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affectEPSS 0.4%CVE-2026-91776HIGHjackson-databind: unbounded growth of the type id cache in TypeDeserializerBase retains every unknown raw type IDEPSS 0.4%CVE-2026-47023MEDIUMVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affeEPSS 0.4%CVE-2026-34267MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.EPSS 0.4%CVE-2025-29484HIGHAn out-of-memory error in the parseABC_NS_SET_INFO function of libming v0.4.8 allows attackers to cause a Denial of Service (DoS) due to allEPSS 0.4%CVE-2026-34278MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.EPSS 0.4%CVE-2025-29487HIGHAn out-of-memory error in the parseABC_STRING_INFO function of libming v0.4.8 allows attackers to cause a Denial of Service (DoS) due to allEPSS 0.4%