Weaknesses of type CWE-400

3,039 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2026-76696MEDIUMUnauthenticated Denial-of-Service (DoS) Vulnerability leads to Service Disruption in HPE Networking EdgeConnect SD-WAN GatewaysEPSS 0.3%CVE-2026-44247MEDIUMVolcano: Webhook server vulnerable to OOM due to unbounded HTTP request body sizeEPSS 0.3%CVE-2026-9002MEDIUMIBM WebSphere eXtremes Scale is affected by uncontrolled resource consumption when XDF is enabledEPSS 0.3%CVE-2024-6126LOWCockpit: authenticated user can kill any process when enabling pam_env's user_readenv optionEPSS 0.3%CVE-2025-48609CRITICALIn multiple functions of MmsProvider.java, there is a possible way to arbitrarily delete files which affect telephony, SMS, and MMS functionEPSS 0.3%CVE-2021-32699MEDIUMAsymmetric Resource Consumption (Amplification) in Docker containers created by WingsEPSS 0.3%CVE-2022-45873MEDIUMsystemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long backtrace. This occurs iEPSS 0.3%CVE-2024-21161MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are PrioEPSS 0.3%CVE-2026-48990MEDIUMjoserfc: b64=false RFC7797 JWS payloads bypass JWSRegistry payload-size limits during deserializationEPSS 0.3%CVE-2025-59464MEDIUMA memory leak in Node.js’s OpenSSL integration occurs when converting `X.509` certificate fields to UTF-8 without freeing the allocated buffEPSS 0.3%CVE-2024-26976HIGHKVM: Always flush async #PF workqueue when vCPU is being destroyedEPSS 0.3%CVE-2023-20268MEDIUMCisco Access Point Software Uncontrolled Resource Consumption VulnerabilityEPSS 0.3%CVE-2025-22892HIGHUncontrolled resource consumption for some OpenVINO™ model server software maintained by Intel(R) before version 2024.4 may allow an unautheEPSS 0.3%CVE-2026-71491HIGHsqlparse: Quadratic O(n²) DoS in group_commentsEPSS 0.3%CVE-2025-61478HIGHAn issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial ofEPSS 0.3%CVE-2026-14321HIGHDivi Dash < 1.0.7 - Unauthenticated Denial of Service via IP Address SpoofingEPSS 0.3%CVE-2026-73175HIGHNozomi Networks Labs identified a CWE-400: Uncontrolled Resource Consumption vulnerability in the OPC UA gateway component of Advantech EKI-EPSS 0.3%CVE-2021-47329MEDIUMscsi: megaraid_sas: Fix resource leak in case of probe failureEPSS 0.3%CVE-2025-46171MEDIUMvBulletin 3.8.7 is vulnerable to a denial-of-service condition via the misc.php?do=buddylist endpoint. If an authenticated user has a sufficEPSS 0.3%CVE-2026-47904MEDIUMCAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)EPSS 0.3%