Weaknesses of type CWE-400

3,000 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2023-33141HIGHYet Another Reverse Proxy (YARP) Denial of Service VulnerabilityEPSS 2.2%CVE-2024-43544HIGHMicrosoft Simple Certificate Enrollment Protocol Denial of Service VulnerabilityEPSS 2.2%CVE-2024-43545HIGHWindows Online Certificate Status Protocol (OCSP) Server Denial of Service VulnerabilityEPSS 2.2%CVE-2021-41186MEDIUMReDoS vulnerability in parser_apache2EPSS 2.2%CVE-2020-14340—A vulnerability was discovered in XNIO where file descriptor leak caused by growing amounts of NIO Selector file handles between garbage colEPSS 2.2%CVE-2022-26477—Denial of service in readExternal methodEPSS 2.2%CVE-2021-32740HIGHRegular Expression Denial of Service in Addressable templatesEPSS 2.2%CVE-2021-22965—A vulnerability in Pulse Connect Secure before 9.1R12.1 could allow an unauthenticated administrator to causes a denial of service when a maEPSS 2.2%CVE-2022-21670MEDIUMUncontrolled Resource Consumption in markdown-itEPSS 2.2%CVE-2025-26641HIGHMicrosoft Message Queuing (MSMQ) Denial of Service VulnerabilityEPSS 2.2%CVE-2025-27473HIGHHTTP.sys Denial of Service VulnerabilityEPSS 2.2%CVE-2020-8185—A denial of service vulnerability exists in Rails <6.0.3.2 that allowed an untrusted user to run any pending migrations on a Rails app runniEPSS 2.2%CVE-2019-12625HIGHClamAV Zip Bomb VulnerabilityEPSS 2.2%CVE-2020-3131MEDIUMCisco Webex Teams Adaptive Cards Denial of Service VulnerabilityEPSS 2.2%CVE-2018-10632—In Moxa NPort 5210, 5230, and 5232 versions 2.9 build 17030709 and prior, the amount of resources requested by a malicious actor are not resEPSS 2.2%CVE-2020-26289HIGHRegular expression Denial of Service in date-and-timeEPSS 2.2%CVE-2018-14659MEDIUMThe Gluster file system through versions 4.1.4 and 3.1.2 is vulnerable to a denial of service attack via use of the 'GF_XATTR_IOSTATS_DUMP_KEPSS 2.2%CVE-2021-3670—MaxQueryDuration not honoured in Samba AD DC LDAPEPSS 2.2%CVE-2016-9367HIGHAn issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions pEPSS 2.2%CVE-2021-21274MEDIUMDenial of service attack via .well-known lookupsEPSS 2.2%