Weaknesses of type CWE-400

3,026 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2026-41310MEDIUMOpenTelemetry .NET Zipkin exporter has unbounded remote endpoint cache leading to memory growthEPSS 0.4%CVE-2026-55594MEDIUMImageMagick: Stack Overflow in MVG decoder due to missing depth check.EPSS 0.4%CVE-2024-38826MEDIUMCVE-2024-38826 Cloud Controller Denial of Service AttackEPSS 0.4%CVE-2024-0157MEDIUMDell Storage Resource Manager, 4.9.0.0 and below, contain(s) a Session Fixation Vulnerability in SRM Windows Host Agent. An adjacent networkEPSS 0.4%CVE-2025-55128MEDIUMHackerOne community member Dang Hung Vi (vidang04) has reported an uncontrolled resource consumption vulnerability in the “userlog-index.phpEPSS 0.4%CVE-2023-40594MEDIUMDenial of Service (DoS) via the ‘printf’ Search FunctionEPSS 0.4%CVE-2024-52974MEDIUMAn issue has been identified where a specially crafted request sent to an Observability API could cause the kibana server to crash. A succeEPSS 0.4%CVE-2025-55588HIGHTOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the fw_ip parameter at /boafrm/formPortFw. This vulneraEPSS 0.4%CVE-2025-55587HIGHTOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the hostname parameter at /boafrm/formMapDelDevice. ThiEPSS 0.4%CVE-2026-58486HIGHHedgeDoc: Denial-of-service via YAML alias expansion in note frontmatterEPSS 0.4%CVE-2026-49249HIGHBoruta: Authenticated atom-exhaustion DoS in BorutaIdentityWeb.UserSettingsController.update/2EPSS 0.4%CVE-2025-50615HIGHA buffer overflow vulnerability has been discovered in Netis WF2880 v2.1.40207 in the FUN_00470c50 function of the cgitest.cgi file. AttackeEPSS 0.4%CVE-2026-83436HIGHVulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Recall Management). Supported versions that are affEPSS 0.4%CVE-2021-31365MEDIUMJunos OS: EX2300, EX3400 and EX4300 Series: An Aggregated Ethernet (AE) interface will go down due to a stream of specific layer 2 framesEPSS 0.4%CVE-2025-55586HIGHTOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the url parameter at /boafrm/formFilter. This vulnerabiEPSS 0.4%CVE-2026-87126HIGHVulnerability in the Oracle Report Manager product of Oracle E-Business Suite (component: Reports Security). Supported versions that are afEPSS 0.4%CVE-2026-83345HIGHVulnerability in the Oracle XML Gateway product of Oracle E-Business Suite (component: Install). Supported versions that are affected are 1EPSS 0.4%CVE-2022-4003LOWA denial-of-service vulnerability could allow an authenticated user to trigger an internal service restart via a specially crafted API requeEPSS 0.4%CVE-2025-46580HIGHZTE GoldenDB Database product has a code-related vulnerabilityEPSS 0.4%CVE-2024-11835HIGHDenial of ServiceEPSS 0.4%