Weaknesses of type CWE-400

3,039 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2026-73746LOWAuthenticated Denial of Service Vulnerability in HPE Networking Fabric Composer APIEPSS 0.3%CVE-2025-27829HIGHAn issue was discovered in Stormshield Network Security (SNS) 4.3.x before 4.3.35. If multicast streams are enabled on different interfaces,EPSS 0.3%CVE-2020-24089—An issue was discovered in ImfHpRegFilter.sys in IOBit Malware Fighter version 8.0.2, allows local attackers to cause a denial of service (DEPSS 0.3%CVE-2026-11790MEDIUM389-ds-base: 389-ds-base: pbkdf2 password storage plugin unbounded iteration count denial of serviceEPSS 0.3%CVE-2025-69199HIGHPterodactyl Wings's websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks under certain circumstancesEPSS 0.3%CVE-2026-81687HIGHopenssl_encrypt before 1.4.9 Denial of Service via KDFEPSS 0.3%CVE-2026-73759MEDIUMUnauthenticated Denial-of-Service Vulnerabilities in AOS-CXEPSS 0.3%CVE-2026-67220MEDIUMRabbitMQ: JMS topic exchange erl_scan atom exhaustionEPSS 0.3%CVE-2026-21588HIGHThis High severity DoS (Denial of Service) vulnerability was introduced in versions 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2,EPSS 0.3%CVE-2026-19645MEDIUMMultiple vulnerabilities in IBM MQ Agent imagesEPSS 0.3%CVE-2023-21061—Product: AndroidVersions: Android kernelAndroid ID: A-229255400References: N/AEPSS 0.3%CVE-2026-67227MEDIUMRabbitMQ: Atom exhaustion: to_atom on global-parameter :nameEPSS 0.3%CVE-2026-74903MEDIUMSiYuan before v3.7.4 Insufficient Access Control via spinBlockDOMEPSS 0.3%CVE-2026-42073MEDIUMOpenClaude's MCP OAuth Callback: State Check Bypass via error Param Leads to DoSEPSS 0.3%CVE-2026-73744LOWAuthenticated Denial of Service Vulnerability in HPE Networking Fabric Composer Web-Based Management InterfaceEPSS 0.3%CVE-2026-10705LOWdask HLL hyperloglog.py nunique_approx resource consumptionEPSS 0.3%CVE-2024-1816MEDIUMUncontrolled Resource Consumption in GitLabEPSS 0.3%CVE-2026-30955MEDIUMGokapi vulnerable to DoS in E2E Metadata ParserEPSS 0.3%CVE-2026-24738MEDIUMgmrtd ReadFile Vulnerable to Denial of Service via Excessive TLV Length ValuesEPSS 0.3%CVE-2026-102414MEDIUMpbkdf2 rehashes long passwords on every iteration, enabling denial of serviceEPSS 0.3%