Weaknesses of type CWE-400

3,039 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2026-34678MEDIUMCAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)EPSS 0.3%CVE-2026-47904MEDIUMCAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)EPSS 0.3%CVE-2026-48434MEDIUMCAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)EPSS 0.3%CVE-2026-47905MEDIUMCAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)EPSS 0.3%CVE-2026-48443MEDIUMCAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)EPSS 0.3%CVE-2026-23809MEDIUMMAC Address Spoofing leads to Inter-BSSID Isolation Bypass Resulting in Traffic RedirectionEPSS 0.3%CVE-2026-34677MEDIUMCAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)EPSS 0.3%CVE-2026-47902MEDIUMCAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)EPSS 0.3%CVE-2025-8449MEDIUMCWE-400: Uncontrolled Resource Consumption vulnerability exists that could cause a denial of service when an authenticated user sends a specEPSS 0.3%CVE-2026-48357MEDIUMCAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)EPSS 0.3%CVE-2021-47313HIGHcpufreq: CPPC: Fix potential memleak in cppc_cpufreq_cpu_initEPSS 0.3%CVE-2026-100542LOWOpenClaw before 2026.8.1 Extraction Limit Bypass via tar.bz2EPSS 0.3%CVE-2026-47262MEDIUMcontainerd image-triggered runtime DoS via unbounded group parsingEPSS 0.3%CVE-2025-37148MEDIUMKernel Panic triggered by Modified Ethernet Frames leads to Denial of Service VulnerabilityEPSS 0.3%CVE-2021-47010HIGHnet: Only allow init netns to set default tcp cong to a restricted algoEPSS 0.3%CVE-2024-44183MEDIUMA logic error was addressed with improved error handling. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS SequoEPSS 0.3%CVE-2026-50171HIGHAngular: Denial of Service (DoS) via OOM in Number Formatting (digitsInfo)EPSS 0.3%CVE-2023-52672HIGHpipe: wakeup wr_wait after setting max_usageEPSS 0.3%CVE-2020-35534—In LibRaw, there is a memory corruption vulnerability within the "crxFreeSubbandData()" function (libraw\src\decoders\crx.cpp) when processiEPSS 0.3%CVE-2023-42983MEDIUMProcessing a file may lead to a denial-of-service or potentially disclose memory contents. This issue is fixed in macOS 14. The issue was adEPSS 0.3%