Weaknesses of type CWE-400

3,026 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2026-33541MEDIUMTSPortal's Uncontrolled User Creation via Validation Side Effects Leads to Potential Denial of ServiceEPSS 0.4%CVE-2024-5055HIGHVulnerability of uncontrolled resource consumption in XAMPPEPSS 0.4%CVE-2026-68904HIGHnode-opcua: TCP Socket Leak (FIN-WAIT-2) via keepalive reconnection cycle - Resource ExhaustionEPSS 0.4%CVE-2026-41721MEDIUMSpring Data Commons Denial of Service via Data BindingEPSS 0.4%CVE-2026-33625HIGHLMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant_dtype in model config loadingEPSS 0.4%CVE-2025-40944HIGHA vulnerability has been identified in SIMATIC ET 200AL IM 157-1 PN (6ES7157-1AB00-0AB0) (All versions), SIMATIC ET 200MP IM 155-5 PN HF (6EEPSS 0.4%CVE-2026-55247CRITICALplone.app.event: Denial of service via iCalendar importEPSS 0.4%CVE-2026-55248CRITICALplone.app.portlets: Denial of service via RSS feed portletEPSS 0.4%CVE-2026-22690LOWpypdf has possible long runtimes for missing /Root object with large /Size valuesEPSS 0.4%CVE-2026-6416LOWTanium addressed an uncontrolled resource consumption vulnerability in Interact.EPSS 0.4%CVE-2024-7708HIGHFor requests that have a body, but reading the body may end up in reading 0 bytes, there is a buffer leak. This is particularly the case forEPSS 0.4%CVE-2026-23940HIGHDenial of Service via Oversized Package UploadEPSS 0.4%CVE-2024-44227HIGHThe issue was addressed with improved memory handling. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An app may be able to EPSS 0.4%CVE-2025-49595MEDIUMn8n Vulnerable to Denial of Service via Malformed Binary Data RequestsEPSS 0.4%CVE-2026-3116MEDIUMImproper Input Validation in Zoom Plugin Webhook HandlerEPSS 0.4%CVE-2026-22815MEDIUMAIOHTTP: Uncapped memory usage possible through aiohttp allowing unlimited trailer headersEPSS 0.4%CVE-2026-94408MEDIUMUncontrolled Resource Consumption in Elasticsearch Leading to denial of serviceEPSS 0.4%CVE-2026-22691LOWpypdf has possible long runtimes for malformed startxrefEPSS 0.4%CVE-2026-30662MEDIUMConcreteCMS v9.4.7 contains a Denial of Service (DoS) vulnerability in the File Manager component. The 'download' method in 'concrete/controEPSS 0.4%CVE-2019-25401HIGHBematech Printer MP-4200 TH Denial of ServiceEPSS 0.4%