Weaknesses of type CWE-400

3,026 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2025-41360HIGHUncontrolled resource consumption vulnerability in IDF and ZLFEPSS 0.4%CVE-2026-61816HIGHzbateson/mail-mime-parser has uncontrolled resource consumption (CPU/memory DoS) parsing untrusted MIMEEPSS 0.4%CVE-2025-6208MEDIUMUncontrolled Memory Consumption in run-llama/llama_indexEPSS 0.4%CVE-2026-61165HIGHVulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge). The supported version EPSS 0.4%CVE-2026-21941MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.EPSS 0.4%CVE-2026-29049MEDIUMmelange: unbounded HTTP download in `melange update-cache` can exhaust disk in CIEPSS 0.4%CVE-2026-21948MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.EPSS 0.4%CVE-2025-25193MEDIUMDenial of Service attack on windows app using NettyEPSS 0.4%CVE-2026-21952MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 9.0.0-9.5.0EPSS 0.4%CVE-2025-9464HIGHRockwell Automation ArmorStart® LT - Multiple Denial-of-Service VulnerabilitiesEPSS 0.4%CVE-2025-37161HIGHUnauthenticated Remote Denial-of-Service (DoS) Vulnerability in Web Management InterfaceEPSS 0.4%CVE-2026-25140HIGHapko affected by potential unbounded resource consumption in expandapk.ExpandApk on attacker-controlled .apk streamsEPSS 0.4%CVE-2026-10675MEDIUMBluetooth Mesh PB-ADV: invalidated provisioning link kept alive indefinitely, blocking (re)provisioning (DoS)EPSS 0.4%CVE-2026-47183MEDIUMZeroconf: Unbounded exception-dedup state retains packet buffers via traceback frame locals, enabling LAN-local memory exhaustionEPSS 0.4%CVE-2023-32665MEDIUMGvariant deserialisation does not match spec for non-normal dataEPSS 0.4%CVE-2026-28412MEDIUMTextream Vulnerable to Uncontrolled Resource Consumption (Denial of Service)EPSS 0.4%CVE-2025-55152MEDIUMoak: ReDoS in x-forwarded-proto and x-forwarded-for headersEPSS 0.4%CVE-2026-33382HIGHDenial of service via unbounded request body sizeEPSS 0.4%CVE-2025-54572MEDIUMRuby SAML DOS vulnerability with large SAML responseEPSS 0.4%CVE-2026-60719CRITICALVulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Supported versions that are affected areEPSS 0.4%