Weaknesses of type CWE-400

3,026 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2026-63136MEDIUMUncontrolled Resource Consumption in Elasticsearch Leading to Denial of ServiceEPSS 0.4%CVE-2026-61160HIGHVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience MaEPSS 0.4%CVE-2026-35441MEDIUMDirectus Affected by GraphQL Alias Amplification Denial-of-Service Due to Missing Query Cost/Complexity LimitsEPSS 0.4%CVE-2020-8299—Citrix ADC and Citrix/NetScaler Gateway 13.0 before 13.0-76.29, 12.1-61.18, 11.1-65.20, Citrix ADC 12.1-FIPS before 12.1-55.238, and Citrix EPSS 0.4%CVE-2026-44019HIGHDocling Core has insufficient validation of image reference URIsEPSS 0.4%CVE-2022-1325—A flaw was found in Clmg, where with the help of a maliciously crafted pandore or bmp file with modified dx and dy header field values it isEPSS 0.4%CVE-2026-40347MEDIUMPython-Multipart affected by Denial of Service via large multipart preamble or epilogue dataEPSS 0.4%CVE-2024-5052HIGHResource consumption vulnerability in Cerberus FTP EnterpriseEPSS 0.4%CVE-2023-30311HIGHAn issue discovered in H3C Magic R365 and H3C Magic R100 routers allows attackers to hijack TCP sessions which could lead to a denial of serEPSS 0.4%CVE-2024-37125HIGHDell SmartFabric OS10 Software, versions 10.5.6.x, 10.5.5.x, 10.5.4.x,10.5.3.x, contains an Uncontrolled Resource Consumption vulnerability.EPSS 0.4%CVE-2024-36743HIGHAn issue in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) when an empty array is processed with oneflow.doEPSS 0.4%CVE-2025-70069HIGHAn issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXConverter.cpp and ConvertMeshMultiMaterial() metEPSS 0.4%CVE-2026-65347MEDIUMThe issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27,EPSS 0.4%CVE-2026-24484MEDIUMImageMagick: Converting multi-layer nested MVG to SVG can cause DoSEPSS 0.4%CVE-2024-42651HIGHNanoMQ v0.17.9 was discovered to contain a heap use-after-free vulnerability via the component sub_Ctx_handle. This vulnerability allows attEPSS 0.4%CVE-2025-54796HIGHCopyparty is vulnerable to Regex Denial of Service (ReDoS) attacks through "Recent Uploads" pageEPSS 0.4%CVE-2025-59472MEDIUMA denial of service vulnerability exists in Next.js versions with Partial Prerendering (PPR) enabled when running in minimal mode. The PPR rEPSS 0.4%CVE-2022-51018HIGHPocketMine-MP before 3.26.5 and 4.0.5 Input Validation via Book PagesEPSS 0.4%CVE-2022-47696—An issue was discovered Binutils objdump before 2.39.3 allows attackers to cause a denial of service or other unspecified impacts via functiEPSS 0.4%CVE-2025-44651HIGHIn TRENDnet TPL-430AP FW1.0, the USERLIMIT_GLOBAL option is set to 0 in the bftpd-related configuration file. This can cause DoS attacks wheEPSS 0.4%