Weaknesses of type CWE-400

3,036 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2026-27308LOWColdFusion | Uncontrolled Resource Consumption (CWE-400)EPSS 0.4%CVE-2026-60185MEDIUMVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affeEPSS 0.4%CVE-2026-27307LOWColdFusion | Uncontrolled Resource Consumption (CWE-400)EPSS 0.4%CVE-2025-50100LOWVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Thread Pooling). Supported versions that are affected are 8.0EPSS 0.4%CVE-2025-61301HIGHDenial-of-analysis in reporting/mongodb.py and reporting/jsondump.py in CAPEv2 (commit 52e4b43, on 2025-05-17) allows attackers who can submEPSS 0.4%CVE-2026-48187MEDIUMEmail with special content can lead to DoSEPSS 0.4%CVE-2021-32455MEDIUMSITEL CAP/PRX vulnerable to a denial of service attackEPSS 0.4%CVE-2026-76693HIGHUnauthenticated Denial-of-Service Vulnerability in HPE Networking EdgeConnect SD-WAN GatewaysEPSS 0.4%CVE-2025-53893HIGHFile Browser Vulnerable to Uncontrolled Memory Consumption Due to Oversized File ProcessingEPSS 0.4%CVE-2026-53493MEDIUMContainerd has image-pull DoS via crafted OCI index graph amplificationEPSS 0.4%CVE-2026-60667HIGHVulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Core). The supported version that EPSS 0.4%CVE-2025-52494HIGHAdacore Ada Web Server (AWS) before 25.2 is vulnerable to a denial-of-service (DoS) condition due to improper handling of SSL handshakes durEPSS 0.4%CVE-2026-40017MEDIUMAn attacker that can send mail to a user can craft a message header whose values are chosen to collide in an internal hash table, which makeEPSS 0.4%CVE-2026-83347MEDIUMVulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3. EasiEPSS 0.4%CVE-2026-40014MEDIUMAn attacker that can send mail to a user can craft a message header that makes the IMAP THREAD command consume CPU disproportionate to the sEPSS 0.4%CVE-2026-45149MEDIUMbrace-expansion: Large numeric range defeats documented `max` DoS protectionEPSS 0.4%CVE-2026-19587MEDIUMUncontrolled Resource Consumption vulnerability in Samsung Open Source rlottie allows Excessive Allocation.EPSS 0.4%CVE-2025-57317HIGHapidoc-core is the core parser library to generate apidoc result following the apidoc-spec. A Prototype Pollution vulnerability in the prePrEPSS 0.4%CVE-2025-60349HIGHAn issue was discovered in Prevx v3.0.5.220 allowing attackers to cause a denial of service via sending IOCTL code 0x22E044 to the pxscan.syEPSS 0.4%CVE-2026-55398MEDIUMMemory management vulnerability in Secure Access clientsEPSS 0.4%