Weaknesses of type CWE-400

3,000 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2021-32839HIGHRegular Expression Denial of Service in sqlparseEPSS 2.3%CVE-2024-43541HIGHMicrosoft Simple Certificate Enrollment Protocol Denial of Service VulnerabilityEPSS 2.3%CVE-2018-1114MEDIUMIt was found that URLResource.getLastModified() in Undertow closes the file descriptors only when they are finalized which can cause file deEPSS 2.3%CVE-2016-8611MEDIUMA vulnerability was found in Openstack Glance. No limits are enforced within the Glance image service for both v1 and v2 `/images` API POST EPSS 2.3%CVE-2024-43506HIGHBranchCache Denial of Service VulnerabilityEPSS 2.3%CVE-2024-43575HIGHWindows Hyper-V Denial of Service VulnerabilityEPSS 2.3%CVE-2024-7592HIGHQuadratic complexity parsing cookies with backslashesEPSS 2.3%CVE-2024-38236HIGHDHCP Server Service Denial of Service VulnerabilityEPSS 2.3%CVE-2019-1644HIGHCisco IoT Field Network Director Resource Exhaustion Denial of Service VulnerabilityEPSS 2.3%CVE-2018-0086—A vulnerability in the application server of the Cisco Unified Customer Voice Portal (CVP) could allow an unauthenticated, remote attacker tEPSS 2.3%CVE-2006-6017MEDIUMWordPress before 2.0.5 does not properly store a profile containing a string representation of a serialized object, which allows remote authEPSS 2.3%CVE-2023-22795—A regular expression based DoS vulnerability in Action Dispatch <6.1.7.1 and <7.0.4.1 related to the If-None-Match header. A specially craftEPSS 2.3%CVE-2024-43515HIGHInternet Small Computer Systems Interface (iSCSI) Denial of Service VulnerabilityEPSS 2.3%CVE-2021-20216—A flaw was found in Privoxy in versions before 3.0.31. A memory leak that occurs when decompression fails unexpectedly may lead to a denial EPSS 2.3%CVE-2025-26652HIGHWindows Standards-Based Storage Management Service Denial of Service VulnerabilityEPSS 2.3%CVE-2025-27470HIGHWindows Standards-Based Storage Management Service Denial of Service VulnerabilityEPSS 2.3%CVE-2018-15464MEDIUMCisco ASR 900 Series Aggregation Services Router Software Denial of Service VulnerabilityEPSS 2.3%CVE-2026-26171HIGH.NET Denial of Service VulnerabilityEPSS 2.3%CVE-2019-1704HIGHCisco Firepower Threat Defense Software SMB Protocol Preprocessor Detection Engine Denial of Service VulnerabilitiesEPSS 2.2%CVE-2024-38149HIGHBranchCache Denial of Service VulnerabilityEPSS 2.2%