Weaknesses of type CWE-400

3,039 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2025-69654HIGHA crafted JavaScript input executed with the QuickJS release 2025-09-13, fixed in commit fcd33c1afa7b3028531f53cd1190a3877454f6b3 (2025-12-1EPSS 0.3%CVE-2024-14036HIGHDräger Core 1.0.5 Denial of Service via Malformed SDC MessageEPSS 0.3%CVE-2026-29776LOWFreeRDP has an Integer Underflow in update_read_cache_bitmap_order Function of FreeRDP's Core LibraryEPSS 0.3%CVE-2026-74797LOWOpenTofu before 1.11.4 Denial of Service via malicious zipEPSS 0.3%CVE-2026-44456MEDIUMHono: bodyLimit() can be bypassed for chunked / unknown-length requestsEPSS 0.3%CVE-2026-81723MEDIUMNLTK before 3.10.3 Quadratic CPU Exhaustion via XMLCorpusViewEPSS 0.3%CVE-2026-19401HIGHRemote UDP DoS by sending multiple DNS Cookie optionsEPSS 0.3%CVE-2026-17465MEDIUMMultiple Vulnerabilities in IBM Concert SoftwareEPSS 0.3%CVE-2025-7105MEDIUMDenial of Service via JavaScript Memory Overflow in danny-avila/librechatEPSS 0.3%CVE-2025-61155MEDIUMThe GameDriverX64.sys kernel-mode anti-cheat driver (v7.23.4.7 and earlier) contains an access control vulnerability in one of its IOCTL hanEPSS 0.3%CVE-2024-54113MEDIUMProcess residence vulnerability in abnormal scenarios in the print module Impact: Successful exploitation of this vulnerability may affect pEPSS 0.3%CVE-2025-54324HIGHAn issue was discovered in NAS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330EPSS 0.3%CVE-2025-65122HIGHRegex Denial of Service in youtube-regex npm package through version 1.0.5.EPSS 0.3%CVE-2024-44154MEDIUMA memory initialization issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7. ProceEPSS 0.3%CVE-2025-56352HIGHIn tinyMQTT commit 6226ade15bd4f97be2d196352e64dd10937c1962 (2024-02-18), the broker mishandles protocol violations during CONNECT packet paEPSS 0.3%CVE-2024-31994MEDIUMMealie vulnerable to a DoS in recipe image importer (GHSL-2023-228)EPSS 0.3%CVE-2026-100558HIGHOpenClaw before 2026.8.1 Resource Exhaustion via WebSocket UpgradeEPSS 0.3%CVE-2025-59440HIGHAn issue was discovered in USIM in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 133EPSS 0.3%CVE-2026-67228MEDIUMRabbitMQ: Atom exhaustion: to_atom on runtime-parameter componentEPSS 0.3%CVE-2024-24769LOWVantage6: No limit on emails sent for password/MFA resetEPSS 0.3%