Weaknesses of type CWE-400

3,030 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2026-43870HIGHApache Thrift: Node.js web_server.js multi-vulnerabilityEPSS 0.4%CVE-2023-32611MEDIUMG_variant_byteswap() can take a long time with some non-normal inputsEPSS 0.4%CVE-2025-30753MEDIUMVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.4%CVE-2023-52098HIGHDenial of Service (DoS) vulnerability in the DMS module. Successful exploitation of this vulnerability will affect availability.EPSS 0.4%CVE-2025-54575MEDIUMImageSharp Triggers an Infinite Loop in its GIF Decoder When Skipping Malformed Comment Extension BlocksEPSS 0.4%CVE-2023-49555MEDIUMAn issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expand_smacro function in the modules/preprocsEPSS 0.4%CVE-2023-5522MEDIUMMobile app freezes when receiving a post with hundreds of emojisEPSS 0.4%CVE-2026-7528HIGHUnauthenticated File Upload Vulnerability Allows Disk Space Exhaustion and Path Disclosure in Langflow OSSEPSS 0.4%CVE-2026-60647HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions tEPSS 0.4%CVE-2025-63561HIGHSummer Pearl Group Vacation Rental Management Platform prior to 1.0.2 is susceptible to a Slowloris-style Denial-of-Service (DoS) condition EPSS 0.4%CVE-2025-66863HIGHAn issue was discovered in function d_discriminator in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service viaEPSS 0.4%CVE-2025-9182HIGHDenial-of-service due to out-of-memory in the Graphics: WebRender componentEPSS 0.4%CVE-2024-5652MEDIUMIn Docker Desktop on Windows before v4.31.0 allows a user in the docker-users group to cause a Windows Denial-of-Service through the exec-path Docker daemon config option in Windows containers modeEPSS 0.4%CVE-2026-33123MEDIUMpypdf has inefficient decoding of array-based streamsEPSS 0.4%CVE-2026-47214HIGHDocling: Unsafe URI and Path Handling in HTML BackendEPSS 0.4%CVE-2026-54260MEDIUMWagtail: Denial of service via unbounded filter specs in the image previewEPSS 0.4%CVE-2026-33443HIGHMemory management error in Secure Access servers prior to 14.55EPSS 0.4%CVE-2025-0426MEDIUMA security issue was discovered in Kubernetes where a large number of container checkpoint requests made to the unauthenticated kubelet readEPSS 0.4%CVE-2026-10224MEDIUMNousResearch hermes-agent Webhook Endpoint feishu.py _handle_webhook_request resource consumptionEPSS 0.4%CVE-2026-84138HIGHDenial-of-service in the PDF Viewer componentEPSS 0.4%