Weaknesses of type CWE-400

3,039 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2026-87828MEDIUMSeraphinite Accelerator < 2.29.24 - Subscriber+ DoS via seraph_accel_State UpdateEPSS 0.3%CVE-2026-62518HIGHVulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions tEPSS 0.3%CVE-2025-43915MEDIUMIn Linkerd edge releases before edge-25.2.1, and Buoyant Enterprise for Linkerd releases 2.13.0–2.13.7, 2.14.0–2.14.10, 2.15.0–2.15.7, 2.16.EPSS 0.3%CVE-2026-22591HIGHFast DDS DDSSQLFilter Recursive Parser Stack Exhaustion (Remote DoS)EPSS 0.3%CVE-2026-72912MEDIUMCyberChef’s pretty-recipe parser vulnerable to client-side ReDoS / CPU exhaustion when parsing a malformed #recipe= URLEPSS 0.3%CVE-2026-6669MEDIUMUnbounded SCRAM iteration count causes CPU exhaustion in PgBouncerEPSS 0.3%CVE-2026-11926HIGHSecurity vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify AccessEPSS 0.3%CVE-2025-46115HIGHAn issue in open5gs v.2.7.3 allows a remote attacker to cause a denial of service via a crafted PDU Session Modification RequestEPSS 0.3%CVE-2025-6599MEDIUMAn uncontrolled resource consumption vulnerability in the web server of Zyxel DX3301-T0 firmware version 5.50(ABVY.6.3)C0 and earlier could EPSS 0.3%CVE-2026-77399MEDIUMicalendar: Denial of service via unbounded VALARM REPEAT expansionEPSS 0.3%CVE-2025-60458MEDIUMUxPlay 1.72 contains a double free vulnerability in its RTSP request handling. A specially crafted RTSP TEARDOWN request can trigger multiplEPSS 0.3%CVE-2026-10802MEDIUMkeystonejs keystone GraphQL API Endpoint output-field.ts resource consumptionEPSS 0.3%CVE-2026-10692MEDIUMjohnhuang316 code-index-mcp search_code_advanced is_safe_regex_pattern redosEPSS 0.3%CVE-2026-20188NONECisco Crosswork Network Controller and Cisco Network Services Orchestrator AdvisoryEPSS 0.3%CVE-2026-67222MEDIUMRabbitMQ: list_to_atom on auth_mechanism URI tokens in amqp_clientEPSS 0.3%CVE-2026-83465HIGHVulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versioEPSS 0.3%CVE-2022-46740MEDIUMThere is a denial of service vulnerability in the Wi-Fi module of the HUAWEI WS7100-20 Smart WiFi Router.Successful exploit could cause a deEPSS 0.3%CVE-2026-12600HIGHUncontrolled memory usage in Innodata Labs’ Poppler JPX decoderEPSS 0.3%CVE-2025-6712MEDIUMMongoDB Server may be susceptible to DoS due to Accumulated Memory AllocationEPSS 0.3%CVE-2026-0517MEDIUMDenial of Service in Secure Access Servers Prior to 14.20.EPSS 0.3%