Weaknesses of type CWE-400

3,039 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2026-13108HIGHDimension Denial-of-ServiceEPSS 0.3%CVE-2026-12611HIGHA client may issue HTTP/2 requests to a Jetty server that result in blocking writes that are never unblocked, eventually causing all threadsEPSS 0.3%CVE-2026-23596MEDIUMUnauthenticated Improper Access Control in management API allows unauthorized service disruptionEPSS 0.3%CVE-2025-54149MEDIUMQsync CentralEPSS 0.3%CVE-2026-69249HIGHpython-cryptography: Duplicate self-signed intermediates can cause exponential path-buildingEPSS 0.3%CVE-2023-45167MEDIUMIBM AIX denial of serviceEPSS 0.3%CVE-2025-54151MEDIUMQsync CentralEPSS 0.3%CVE-2025-54150MEDIUMQsync CentralEPSS 0.3%CVE-2025-41361HIGHUncontrolled resource consumption vulnerability in IDF and ZLFEPSS 0.3%CVE-2026-86135HIGHDimension CSRF Vulnerability in Database Snapshot Creation Allows Denial of ServiceEPSS 0.2%CVE-2023-52602HIGHjfs: fix slab-out-of-bounds Read in dtSearchEPSS 0.2%CVE-2025-58767LOWREXML has a DoS condition when parsing malformed XML fileEPSS 0.2%CVE-2021-0092MEDIUMImproper access control in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable a denial of service vEPSS 0.2%CVE-2024-25452MEDIUMBento4 v1.6.0-640 was discovered to contain an out-of-memory bug via the AP4_UrlAtom::AP4_UrlAtom() function.EPSS 0.2%CVE-2026-49324MEDIUMIndian Scout Bobber 2025 WCM brute-forceEPSS 0.2%CVE-2021-46939MEDIUMtracing: Restructure trace_clock_global() to never blockEPSS 0.2%CVE-2026-60620MEDIUMVulnerability in the JD Edwards EnterpriseOne Configurator product of Oracle JD Edwards (component: Configuration Management). The supportEPSS 0.2%CVE-2024-39557HIGHJunos OS Evolved: MAC table changes cause a memory leakEPSS 0.2%CVE-2024-34035MEDIUMAn issue was discovered in O-RAN Near Realtime RIC H-Release. To trigger the crashing of the e2mgr, an adversary must flood the system with EPSS 0.2%CVE-2026-2405MEDIUMCWE-400 Uncontrolled Resource Consumption vulnerability exists that could cause excessive troubleshooting zip file creation and denial of seEPSS 0.2%