Weaknesses of type CWE-400

3,039 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2026-10692MEDIUMjohnhuang316 code-index-mcp search_code_advanced is_safe_regex_pattern redosEPSS 0.3%CVE-2026-83465HIGHVulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versioEPSS 0.3%CVE-2022-46740MEDIUMThere is a denial of service vulnerability in the Wi-Fi module of the HUAWEI WS7100-20 Smart WiFi Router.Successful exploit could cause a deEPSS 0.3%CVE-2025-6712MEDIUMMongoDB Server may be susceptible to DoS due to Accumulated Memory AllocationEPSS 0.3%CVE-2026-12600HIGHUncontrolled memory usage in Innodata Labs’ Poppler JPX decoderEPSS 0.3%CVE-2026-100651HIGHvllm before 0.29.0 Denial of Service via Decoder Prompt Length BypassEPSS 0.3%CVE-2026-0517MEDIUMDenial of Service in Secure Access Servers Prior to 14.20.EPSS 0.3%CVE-2025-58349CRITICALAn issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330,EPSS 0.3%CVE-2025-31251MEDIUMThe issue was addressed with improved input sanitization. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5EPSS 0.3%CVE-2023-35925MEDIUMFastAsyncWorldEdit vulnerable to Uncontrolled Resource ConsumptionEPSS 0.3%CVE-2024-57412HIGHAn issue in SunOS Omnios v5.11 allows attackers to cause a Denial of Service (DoS) via repeatedly sending crafted TCP packets.EPSS 0.3%CVE-2026-22021MEDIUMVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). EPSS 0.3%CVE-2022-40480MEDIUMNordic Semiconductor, Microchip Technology NRF5340-DK DT100112 was discovered to contain an issue which allows attackers to cause a Denial oEPSS 0.3%CVE-2021-4022—A vulnerability was found in rizin. The bug involves an ELF64 binary for the HPPA architecture. When a specially crafted binarygets analysedEPSS 0.3%CVE-2026-22017MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.EPSS 0.3%CVE-2026-22009MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.EPSS 0.3%CVE-2026-102277MEDIUMbrace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU denial of serviceEPSS 0.3%CVE-2026-101911MEDIUMip-address: Address6 builds a parse diagnostic proportional to the input with no length bound, allowing a single long string to stall or crash the processEPSS 0.3%CVE-2026-59980MEDIUMhpack: Unbounded variable integer decoding can cause run-away computation on malformed inputEPSS 0.3%CVE-2025-8872HIGHA specially crafted packet can cause the OSFPv3 process to have high CPU utilization which may result in the OSFPv3 process being restartedEPSS 0.3%