Weaknesses of type CWE-400

3,036 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2026-22228MEDIUMImproper Input Validation Leading to DoS on TP-Link Archer BE230EPSS 0.3%CVE-2014-2343—Triangle MicroWorks SCADA Data Gateway Resource ExhaustionEPSS 0.3%CVE-2025-65947HIGHthread-amount is Vulnerable to Resource Exhaustion (Memory and Handle Leaks) on Windows and macOSEPSS 0.3%CVE-2025-30188HIGHMalicious or unintentional API requests can be used to add significant amount of data to caches. Caches may evict information that is requirEPSS 0.3%CVE-2025-64388CRITICALDenial of service through specific packetsEPSS 0.3%CVE-2025-7579MEDIUMchinese-poetry server.js redosEPSS 0.3%CVE-2025-70047HIGHAn issue pertaining to CWE-400: Uncontrolled Resource Consumption was discovered in Nexusoft NexusInterface v3.2.0-beta.2.EPSS 0.3%CVE-2024-8892MEDIUMUncontrolled Resource Consumption vulnerability on CIRCUTOR TCP2RS+EPSS 0.3%CVE-2026-17463MEDIUMIBM® Db2® could allow a remote authenticated attacker to cause a denial of service due to uncontrolled resource consumptionEPSS 0.3%CVE-2020-18770—An issue was discovered in function zzip_disk_entry_to_file_header in mmapped.c in zziplib 0.13.69, which will lead to a denial-of-service.EPSS 0.3%CVE-2026-22740MEDIUMSpring Framework DoS with Multipart Temp Files in WebFluxEPSS 0.3%CVE-2026-100661HIGHNetty HTTP/3 QPACK Prefixed Integer DoS via Unbounded AccumulationEPSS 0.3%CVE-2026-100662HIGHNetty HTTP/3 QPACK encoder-stream unbounded memory exhaustion DoSEPSS 0.3%CVE-2026-8856HIGHIBM HTTP Server is affected by multiple vulnerabilitiesEPSS 0.3%CVE-2025-29490MEDIUMlibming v0.4.8 was discovered to contain a segmentation fault via the decompileCALLMETHOD function. This vulnerability allows attackers to cEPSS 0.3%CVE-2025-65781HIGHAn issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Attachment upload API treats the AEPSS 0.3%CVE-2026-66071MEDIUMRabbitMQ: Atom exhaustion: OAuth2 JWT tag: scope valuesEPSS 0.3%CVE-2026-22745MEDIUMCVE-2026-22745 : Denial of service in static resource handling on Windows platformsEPSS 0.3%CVE-2024-7294HIGHUncontrolled resource consumption of anonymous endpointsEPSS 0.3%CVE-2026-67408HIGHRabbitMQ: Stream Management Super-Stream Binding Keys Allocation Allows Low-Privilege Node Denial of ServiceEPSS 0.3%