Weaknesses of type CWE-400

3,027 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2025-54572MEDIUMRuby SAML DOS vulnerability with large SAML responseEPSS 0.4%CVE-2026-93590MEDIUMImageMagick before 7.1.2-31 Policy Bypass in UHDR encoderEPSS 0.4%CVE-2023-45150MEDIUMInviting excessive long email addresses to a calendar event makes the Nextcloud server unresponsiveEPSS 0.4%CVE-2025-50057MEDIUMExtension - rsjoomla.com - DOS vulnerability RSFiles! component 1.16.3-1.17.7 for JoomlaEPSS 0.4%CVE-2025-62260HIGHLiferay Portal 7.4.0 through 7.4.3.99, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and EPSS 0.4%CVE-2023-1981MEDIUMA vulnerability was found in the avahi library. This flaw allows an unprivileged user to make a dbus call, causing the avahi daemon to crashEPSS 0.4%CVE-2025-48041HIGHSSH_FXP_OPENDIR may Lead to Exhaustion of File HandlesEPSS 0.4%CVE-2025-48039MEDIUMUnverified Paths can Cause Excessive Use of System ResourcesEPSS 0.4%CVE-2025-11681HIGHDenial of Service condition in M-Files ServerEPSS 0.4%CVE-2025-48038MEDIUMUnverified File Handles can Cause Excessive Use of System ResourcesEPSS 0.4%CVE-2025-32436HIGHAutoGPT has a DoS vulnerability in AddAudioToVideoBlockEPSS 0.4%CVE-2026-60582HIGHVulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). The supported versioEPSS 0.4%CVE-2021-1564MEDIUMCisco Video Surveillance 7000 Series IP Cameras Cisco Discovery and Link Layer Discovery Protocol Memory Leak VulnerabilitiesEPSS 0.4%CVE-2021-1563MEDIUMCisco Video Surveillance 7000 Series IP Cameras Cisco Discovery and Link Layer Discovery Protocol Memory Leak VulnerabilitiesEPSS 0.4%CVE-2026-76400MEDIUMDenial of Service (DoS) through the REST API in Splunk Connect for KafkaEPSS 0.4%CVE-2026-40019MEDIUMAn unauthenticated attacker can send a truncated quoted argument to the ManageSieve login process, which makes it spin in an infinite loop cEPSS 0.4%CVE-2021-0292MEDIUMJunos OS Evolved: Memory leak in arpd or ndp processes can lead to Denial of Service (DoS)EPSS 0.4%CVE-2025-6297HIGHdpkg-deb: Fix cleanup for control member with restricted directoriesEPSS 0.4%CVE-2022-31030MEDIUMcontainerd CRI plugin: Host memory exhaustion through ExecSyncEPSS 0.4%CVE-2023-32611MEDIUMG_variant_byteswap() can take a long time with some non-normal inputsEPSS 0.4%