Weaknesses of type CWE-400

3,039 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2025-56352HIGHIn tinyMQTT commit 6226ade15bd4f97be2d196352e64dd10937c1962 (2024-02-18), the broker mishandles protocol violations during CONNECT packet paEPSS 0.3%CVE-2026-10156MEDIUMOpen5GS nf-instances Endpoint nnrf-handler.c handle_amf_info resource consumptionEPSS 0.3%CVE-2025-57440HIGHThe Blackmagic ATEM Mini Pro 2.7 exposes an undocumented Telnet service on TCP port 9993, which accepts unauthenticated plaintext commands fEPSS 0.3%CVE-2024-33259MEDIUMJerryscript commit cefd391 was discovered to contain a segmentation violation via the component scanner_seek at jerry-core/parser/js/js-scanEPSS 0.3%CVE-2024-53423MEDIUMAn issue in Open Network Foundation ONOS v2.7.0 allows attackers to cause a Denial of Service (DoS) via supplying crafted packets.EPSS 0.3%CVE-2024-42397MEDIUMUnauthenticated Denial-of-Service (DoS) Vulnerabilities in the AP Certificate Management Service Accessed by the PAPI ProtocolEPSS 0.3%CVE-2026-34673MEDIUMCAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)EPSS 0.3%CVE-2021-33135MEDIUMUncontrolled resource consumption in the Linux kernel drivers for Intel(R) SGX may allow an authenticated user to potentially enable denial EPSS 0.3%CVE-2025-49460MEDIUMZoom Workplace Clients - Argument InjectionEPSS 0.3%CVE-2026-60669MEDIUMVulnerability in the PeopleSoft Enterprise HCM Global Payroll Mexico product of Oracle PeopleSoft (component: Global Payroll for Mexico). EPSS 0.3%CVE-2026-96764MEDIUMkvcache-ai mooncake Regular Expression GetReplicaListByRegex allocation of resourcesEPSS 0.3%CVE-2026-61247MEDIUMVulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that EPSS 0.3%CVE-2025-66453MEDIUMRhino vulnerable high CPU usage and potential DoS when passing specific numbers to toFixed() functionEPSS 0.3%CVE-2021-3764—A memory leak flaw was found in the Linux kernel's ccp_run_aes_gcm_cmd() function that allows an attacker to cause a denial of service. The EPSS 0.3%CVE-2025-24199MEDIUMAn uncontrolled format string issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14EPSS 0.3%CVE-2026-61123MEDIUMVulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affeEPSS 0.3%CVE-2025-46304MEDIUMThe issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and iPadOS 26.2, macOS SeEPSS 0.3%CVE-2026-76696MEDIUMUnauthenticated Denial-of-Service (DoS) Vulnerability leads to Service Disruption in HPE Networking EdgeConnect SD-WAN GatewaysEPSS 0.3%CVE-2026-44247MEDIUMVolcano: Webhook server vulnerable to OOM due to unbounded HTTP request body sizeEPSS 0.3%CVE-2026-63457MEDIUMA potential denial of service vulnerability exists in HPE Integrated Lights-Out 6 (iLO 6) prior to v1.78.EPSS 0.3%