Weaknesses of type CWE-400

3,026 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2018-16878MEDIUMA flaw was found in pacemaker up to and including version 2.0.1. An insufficient verification inflicted preference of uncontrolled processesEPSS 0.4%CVE-2026-10069HIGHShibby Tomato miniupnpd resource consumptionEPSS 0.4%CVE-2022-4986HIGHHirschmann EagleSDV Denial of Service via TLSEPSS 0.4%CVE-2024-57079HIGHA prototype pollution in the lib.deepMerge function of @zag-js/core v0.50.0 allows attackers to cause a Denial of Service (DoS) via supplyinEPSS 0.4%CVE-2024-44192MEDIUMThe issue was addressed with improved checks. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2,EPSS 0.4%CVE-2023-45028MEDIUMQTS, QuTS hero, QuTScloudEPSS 0.4%CVE-2026-7493MEDIUMAppointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.11.5 - Unauthenticated Denial of ServiceEPSS 0.4%CVE-2026-54338MEDIUMJupyterHub: Unauthenticated Denial of Service via Unbounded Username Logging on Failed LoginEPSS 0.4%CVE-2026-90928HIGHFile Browser through 2.63.23 Memory Exhaustion via subtitle endpointEPSS 0.4%CVE-2026-62326MEDIUMWeblate Has Uncontrolled Resource Consumption viaEPSS 0.4%CVE-2026-86255HIGHwger before 2.5 Uncontrolled Resource Consumption via date_sequenceEPSS 0.4%CVE-2026-90927HIGHfilebrowser through 2.63.23 Denial of Service via unbounded WebSocket messageEPSS 0.4%CVE-2026-86204HIGHPocketMine-MP before 5.39.2 Denial of Service via ModalFormResponsePacketEPSS 0.4%CVE-2026-91979HIGHVikunja before 2.6.0 Denial of Service via Decompression BombEPSS 0.4%CVE-2026-91969HIGHvikunja before 2.6.0 Resource Exhaustion via CSV MigrationEPSS 0.4%CVE-2026-61617HIGHPterodactyl Wings SFTP write path does not enforce disk quota, allowing node-wide disk exhaustionEPSS 0.4%CVE-2026-91971HIGHVikunja before 2.6.0 Denial of Service via Avatar UploadEPSS 0.4%CVE-2024-54546HIGHThe issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15. An app may be able to cause unexpected systeEPSS 0.4%CVE-2026-57914MEDIUMApache Kerby: StackOverflow on parsing deeply nested ASN1 structuresEPSS 0.4%CVE-2026-48987MEDIUMpyLoad: Unbounded Memory Growth Leading to DoS and Potential DDoS in EventManagerEPSS 0.4%