Weaknesses of type CWE-400

3,026 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2026-28967MEDIUMA denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPEPSS 0.4%CVE-2026-83457HIGHVulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations). Supported versionEPSS 0.4%CVE-2024-43105MEDIUMExcessive Resource Consumption via `/export`EPSS 0.4%CVE-2022-23951MEDIUMIn Keylime before 6.3.0, quote responses from the agent can contain possibly untrusted ZIP data which can lead to zip bombs.EPSS 0.4%CVE-2025-60790MEDIUMProcessWire CMS 3.0.246 allows a low-privileged user with lang-edit to upload a crafted ZIP to Language Support that is auto-extracted withoEPSS 0.4%CVE-2026-43804MEDIUMThis issue was addressed through improved state management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, EPSS 0.4%CVE-2023-49557MEDIUMAn issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the yasm_section_bcs_first function in the libyasmEPSS 0.4%CVE-2026-47706MEDIUMStrawberry GraphQL has a Circular Fragment Reference DOSEPSS 0.4%CVE-2026-48988MEDIUMmarkdown-it: Quadratic complexity DoS in smartquotes rule via replaceAt string operationsEPSS 0.4%CVE-2024-42399MEDIUMUnauthenticated Denial-of-Service (DoS) Vulnerabilities in the Soft AP Daemon Service Accessed by the PAPI ProtocolEPSS 0.4%CVE-2021-44320HIGHParrot AR.Drone version 1 and 2 does not employ a suitable mechanism to prevent denial-of-service (DoS) attacks. An attacker can harm the deEPSS 0.4%CVE-2024-42398MEDIUMUnauthenticated Denial-of-Service (DoS) Vulnerabilities in the Soft AP Daemon Service Accessed by the PAPI ProtocolEPSS 0.4%CVE-2025-27097MEDIUMCache variables with the operations when transforms exist on the root level even if variables change in the further requests with the same operationEPSS 0.4%CVE-2026-42127HIGHPre-authentication denial of service in the public dashboard query endpointEPSS 0.4%CVE-2026-41146HIGHfacil.io and downstream iodine ruby gem vulnerable to uncontrolled resource consumption and loop with unreachable exit conditionEPSS 0.4%CVE-2025-48040MEDIUMMalicious Key Exchange Messages may Lead to Excessive Resource ConsumptionEPSS 0.4%CVE-2024-14033HIGHHirschmann EagleSDV Denial of Service via TLSEPSS 0.4%CVE-2026-86347HIGHMISP Missing Authorization on Template File Upload Allows Authenticated Disk ExhaustionEPSS 0.4%CVE-2026-10650MEDIUMwarmcat libwebsockets SSH Protocol sshd.c lws_ssh_parse_plaintext resource consumptionEPSS 0.4%CVE-2026-21435MEDIUMwebtransport-go CloseWithError can block indefinitelyEPSS 0.4%