Weaknesses of type CWE-400

3,026 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2022-47696—An issue was discovered Binutils objdump before 2.39.3 allows attackers to cause a denial of service or other unspecified impacts via functiEPSS 0.4%CVE-2025-66960HIGHAn issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the fs/ggml/gguf.go, function readGGUFV1String reads EPSS 0.4%CVE-2025-52867MEDIUMQsync CentralEPSS 0.4%CVE-2022-43893LOWIBM Security Verify Privilege denial of serviceEPSS 0.4%CVE-2026-48525MEDIUMPyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload segment in b64=false detached JWSEPSS 0.4%CVE-2024-41434MEDIUMPingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component (*Column).GetDecimal. This allows attackers to cause a DenEPSS 0.4%CVE-2024-35194MEDIUMStacklok Minder vulnerable to denial of service from maliciously crafted templatesEPSS 0.4%CVE-2026-61186CRITICALVulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version tEPSS 0.4%CVE-2026-58042MEDIUMA flaw in Node.js can cause dns.resolveAny() Aborts the Node.js Process When a DNS Response Contains More Than 256 A Records. Repeated trEPSS 0.4%CVE-2025-59975HIGHJunos Space: Flooding device with inbound API calls leads to WebUI and CLI management access DoSEPSS 0.4%CVE-2020-1678MEDIUMJunos OS and Junos OS Evolved: RPD can crash due to a slow memory leak.EPSS 0.4%CVE-2025-27421HIGHGoroutine Leak in Abacus SSE ImplementationEPSS 0.4%CVE-2024-37281MEDIUMKibana Denial of Service issueEPSS 0.4%CVE-2026-76000MEDIUMColdFusion | Uncontrolled Resource Consumption (CWE-400)EPSS 0.4%CVE-2024-33001MEDIUMDenial of service (DOS) in SAP NetWeaver and ABAP platformEPSS 0.4%CVE-2025-5890MEDIUMactions toolkit glob internal-pattern.ts globEscape redosEPSS 0.4%CVE-2026-56725HIGHZammad: Denial of Service via OTRS Import ControllerEPSS 0.4%CVE-2026-49343MEDIUMKlever-Go KVM: Throttler slot leak in trie account-data sync causes epoch bootstrap / state sync DoSEPSS 0.4%CVE-2026-82294MEDIUMUncontrolled Resource Consumption in Elasticsearch Leading to Denial of ServiceEPSS 0.4%CVE-2026-16265MEDIUMWP Maps < 4.9.7 - Subscriber+ Denial of ServiceEPSS 0.4%