Weaknesses of type CWE-400

3,026 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2025-67731HIGHServify Express does not enforce rate limiting when parsing JSONEPSS 0.4%CVE-2025-54604HIGHBitcoin Core through 29.0 allows Uncontrolled Resource Consumption (issue 1 of 2).EPSS 0.4%CVE-2025-54605HIGHBitcoin Core through 29.0 allows Uncontrolled Resource Consumption (issue 2 of 2).EPSS 0.4%CVE-2025-56264HIGHThe /api/comment endpoint in zhangyd-c OneBlog 2.3.9 contains a denial-of-service vulnerability.EPSS 0.4%CVE-2026-60846MEDIUMVulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versioEPSS 0.4%CVE-2022-2962HIGHA DMA reentrancy issue was found in the Tulip device emulation in QEMU. When Tulip reads or writes to the rx/tx descriptor or copies the rx/EPSS 0.4%CVE-2023-50121MEDIUMAutel EVO NANO drone flight control firmware version 1.6.5 is vulnerable to denial of service (DoS).EPSS 0.4%CVE-2026-27859MEDIUMA mail message containing excessive amount of RFC 2231 MIME parameters causes LMTP to use too much CPU. A suitably formatted mail message caEPSS 0.4%CVE-2026-83459MEDIUMVulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-media-multipart). Supported versions that are affectedEPSS 0.4%CVE-2025-67835MEDIUMPaessler PRTG Network Monitor before 25.4.114 allows Denial-of-Service (DoS) by an authenticated attacker via the Notification Contacts funcEPSS 0.4%CVE-2026-53596MEDIUMFreeScout has unrestricted file upload without rate limiting that leads to resource exhaustion (DoS)EPSS 0.4%CVE-2026-83458MEDIUMVulnerability in the Helidon product of Oracle Fusion Middleware (component: JSON). Supported versions that are affected are 4.0.0-4.5.4. EEPSS 0.4%CVE-2026-19475MEDIUMSQL Data Source Plugin: OOM DoS via $__timeGroup macroEPSS 0.4%CVE-2026-51106CRITICALAn issue in TokTok qTox v1.18.4 allows a local attacker to cause a denial of service via the src/persistence/serialize.cpp componentEPSS 0.4%CVE-2026-19113MEDIUMUnauthenticated denial of service via unbounded request body processingEPSS 0.4%CVE-2026-59315MEDIUMSpring Cloud Config Monitor Denial of ServiceEPSS 0.4%CVE-2024-57074HIGHA prototype pollution in the lib.merge function of xe-utils v3.5.31 allows attackers to cause a Denial of Service (DoS) via supplying a crafEPSS 0.4%CVE-2025-71418MEDIUMPocketMine-MP before 5.25.2 Denial of Service via explodeEPSS 0.4%CVE-2024-57085HIGHA prototype pollution in the function deepMerge of @stryker-mutator/util v8.6.0 allows attackers to cause a Denial of Service (DoS) via suppEPSS 0.4%CVE-2024-24424HIGHA reachable assertion in the decode_access_point_name_ie function of Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2EPSS 0.4%