Weaknesses of type CWE-400

3,000 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2023-34462MEDIUMnetty-handler SniHandler 16MB allocationEPSS 2.5%CVE-2016-10523—MQTT before 3.4.6 and 4.0.x before 4.0.5 allows specifically crafted MQTT packets to crash the application, making a DoS attack feasible witEPSS 2.5%CVE-2026-45591HIGHASP.NET Core Denial of Service VulnerabilityEPSS 2.4%CVE-2026-33116HIGH.NET, .NET Framework, and Visual Studio Denial of Service VulnerabilityEPSS 2.4%CVE-2022-24863HIGHDenial of service in http-swaggerEPSS 2.4%CVE-2023-36703HIGHDHCP Server Service Denial of Service VulnerabilityEPSS 2.4%CVE-2019-6559—Moxa IKS and EDS allow remote authenticated users to cause a denial of service via a specially crafted packet, which may cause the switch toEPSS 2.4%CVE-2020-1700MEDIUMA flaw was found in the way the Ceph RGW Beast front-end handles unexpected disconnects. An authenticated attacker can abuse this flaw by maEPSS 2.4%CVE-2024-38015HIGHWindows Remote Desktop Gateway (RD Gateway) Denial of Service VulnerabilityEPSS 2.4%CVE-2024-21386HIGH.NET Denial of Service VulnerabilityEPSS 2.4%CVE-2018-0230—A vulnerability in the internal packet-processing functionality of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 SeEPSS 2.4%CVE-2023-36431HIGHMicrosoft Message Queuing (MSMQ) Denial of Service VulnerabilityEPSS 2.4%CVE-2023-36579HIGHMicrosoft Message Queuing (MSMQ) Denial of Service VulnerabilityEPSS 2.4%CVE-2025-21289HIGHMicrosoft Message Queuing (MSMQ) Denial of Service VulnerabilityEPSS 2.4%CVE-2018-0233—A vulnerability in the Secure Sockets Layer (SSL) packet reassembly functionality of the detection engine in Cisco Firepower System SoftwareEPSS 2.4%CVE-2025-21290HIGHMicrosoft Message Queuing (MSMQ) Denial of Service VulnerabilityEPSS 2.4%CVE-2025-21270HIGHMicrosoft Message Queuing (MSMQ) Denial of Service VulnerabilityEPSS 2.4%CVE-2020-26257MEDIUMDenial of service attack via incorrect parameters to federation APIsEPSS 2.4%CVE-2022-35769HIGHWindows Point-to-Point Protocol (PPP) Denial of Service VulnerabilityEPSS 2.4%CVE-2020-5236MEDIUMCatastrophic backtracking in regex allows Denial of Service in WaitressEPSS 2.4%