Weaknesses of type CWE-400

3,039 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2025-50861MEDIUMThe Lotus Cars Android app (com.lotus.carsdomestic.intl) 1.2.8 contains an exported component, PushDeepLinkActivity, which is accessible witEPSS 0.3%CVE-2024-50354MEDIUMOut-of-memory during deserialization with crafted inputsEPSS 0.3%CVE-2025-25208MEDIUMRhcl: authorino denial of service through authpolicy with sharedsecretref severityEPSS 0.3%CVE-2025-57751HIGHDenial-of-Service attack in pyLoad CNL Blueprint using dukpy.evaljsEPSS 0.3%CVE-2024-22588MEDIUMKwik commit 745fd4e2 does not discard unused encryption keys.EPSS 0.3%CVE-2026-22004MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0EPSS 0.3%CVE-2025-43706HIGHAn issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2400, 1580, 9110, W920,EPSS 0.3%CVE-2026-22002MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.EPSS 0.3%CVE-2026-21998MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.EPSS 0.3%CVE-2026-22005MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.EPSS 0.3%CVE-2026-87721HIGHDenial of Service via Exponential Backtracking in ANTLR Search Query Parser in Gerrit Code ReviewEPSS 0.3%CVE-2026-87722HIGHRegular Expression Denial of Service (ReDoS) in Search Query Predicates and REST Filter Endpoints in Gerrit Code ReviewEPSS 0.3%CVE-2026-86420MEDIUMImageMagick before 7.1.2-30 Denial of Service Memory BudgetEPSS 0.3%CVE-2025-8849MEDIUMDenial of Service in danny-avila/librechatEPSS 0.3%CVE-2022-29202MEDIUMDenial of service in TensorFlow due to lack of validation in `tf.ragged.constant`EPSS 0.3%CVE-2026-22239CRITICALEmail Sending Vulnerability in BLUVOYIXEPSS 0.3%CVE-2023-1654MEDIUMDenial of Service in gpac/gpacEPSS 0.3%CVE-2024-40841HIGHAn out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7. ProcesEPSS 0.3%CVE-2025-10470HIGHDenial-of-Service via Magic Link Authentication in WSO2 Identity Server Allows Service UnavailabilityEPSS 0.3%CVE-2025-63288HIGHIn Open5GS 2.7.6, AMF crashes when receiving an abnormal NGSetupRequest message, resulting in denial of service.EPSS 0.3%