Weaknesses of type CWE-400

3,036 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2026-55399MEDIUMResource exhaustion vulnerability in the Secure Access publisherEPSS 0.4%CVE-2026-54786LOWWasmtime: Leak in WASIp1 `fd_renumber` implementationEPSS 0.4%CVE-2026-57204MEDIUMpypdf: Missing stream length values ignore defined limitsEPSS 0.4%CVE-2024-31399MEDIUMExcessive platform resource consumption within a loop issue exists in Cybozu Garoon 5.0.0 to 5.15.2. If this vulnerability is exploited, proEPSS 0.4%CVE-2026-13149HIGHbrace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number oEPSS 0.4%CVE-2022-27640—A vulnerability has been identified in SIMATIC CP 442-1 RNA (All versions < V1.5.18), SIMATIC CP 443-1 RNA (All versions < V1.5.18). The affEPSS 0.4%CVE-2024-21658MEDIUMInsufficient control of region value length in discourse-calendarEPSS 0.4%CVE-2026-22540CRITICALDENIAL OF SERVICE VIA ARP PACKETSEPSS 0.4%CVE-2026-16376HIGHDenial-of-service in the Graphics: WebGPU componentEPSS 0.4%CVE-2025-2811MEDIUMGL.iNet GL-A1300 Slate Plus API redosEPSS 0.4%CVE-2025-66019MEDIUMpypdf manipulated LZWDecode streams can exhaust RAMEPSS 0.4%CVE-2026-21485HIGHiccDEV Undefined Behavior (UB) and Out of Memory in CIccProfile::LoadTag()EPSS 0.4%CVE-2021-3759—A memory overflow vulnerability was found in the Linux kernel’s ipc functionality of the memcg subsystem, in the way a user calls the semgetEPSS 0.4%CVE-2026-60182MEDIUMVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Clone Plugin). Supported versions that are affEPSS 0.4%CVE-2026-60184MEDIUMVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affeEPSS 0.4%CVE-2026-60186MEDIUMVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions EPSS 0.4%CVE-2026-33607MEDIUMAn attacker that has valid credentials can use IMAP LIST command to consume CPU. This can cause degradation or denial of service for IMAP. MEPSS 0.4%CVE-2026-60177MEDIUMVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Clone Plugin). Supported versions that are affEPSS 0.4%CVE-2026-60187MEDIUMVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affeEPSS 0.4%CVE-2026-47012MEDIUMVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affectEPSS 0.4%