Weaknesses of type CWE-400

3,026 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2026-47046HIGHVulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Easily exploitableEPSS 0.4%CVE-2026-46866HIGHVulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen). Supported veEPSS 0.4%CVE-2024-56528HIGHThis vulnerability affects Snowplow Collector 3.x before 3.3.0 (unless it’s set up behind a reverse proxy that establishes payload limits). EPSS 0.4%CVE-2025-50103MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: LDAP Auth). Supported versions that are affected arEPSS 0.4%CVE-2024-47212HIGHAn issue was discovered in Iglu Server 0.13.0 and below. It involves sending very large payloads to a particular API endpoint of Iglu ServerEPSS 0.4%CVE-2025-20058HIGHBIG-IP message routing vulnerabilityEPSS 0.4%CVE-2026-57224MEDIUMSuricata dhcp: unbounded transactions in unidirectional traffic can lead to resource exhaustionEPSS 0.4%CVE-2024-47535MEDIUMDenial of Service attack on windows app using NettyEPSS 0.4%CVE-2025-21087HIGHTMM VulnerabilityEPSS 0.4%CVE-2024-29153HIGHA vulnerability was discovered in Samsung Mobile Processor, Wearable Processor, and Modems with versions Exynos 9820, Exynos 9825, Exynos 98EPSS 0.4%CVE-2024-24943MEDIUMIn JetBrains Toolbox App before 2.2 a DoS attack was possible via a malicious SVG imageEPSS 0.4%CVE-2023-1071LOWAn issue has been discovered in GitLab affecting all versions from 15.5 before 15.8.5, all versions starting from 15.9 before 15.9.4, all veEPSS 0.4%CVE-2022-40513HIGHUncontrolled resource consumption in WLAN Firmware.EPSS 0.4%CVE-2024-24975LOW Denial of Service for mobile app users due to automatic code highlightingEPSS 0.4%CVE-2023-21339HIGHIn Minikin, there is a possible way to trigger ANR by showing a malicious message due to resource exhaustion. This could lead to remote deniEPSS 0.4%CVE-2026-47881MEDIUMDenial of Service in Spring Batch FlatFileItemReader via Malformed Input FileEPSS 0.4%CVE-2026-33445HIGHMemory management vulnerability in Secure Access serversEPSS 0.4%CVE-2025-0114HIGHPAN-OS: Denial of Service (DoS) in GlobalProtectEPSS 0.4%CVE-2025-55102HIGHA denial-of-service vulnerability exists in the NetX IPv6 component functionality of Eclipse ThreadX NetX Duo. A specially crafted network pEPSS 0.4%CVE-2021-0257MEDIUMJunos OS: MX Series, EX9200 Series: Trio-based MPCs memory leak in VPLS with integrated routing and bridging (IRB) interfaceEPSS 0.4%