Weaknesses of type CWE-400

3,039 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2025-63811HIGHAn issue was discovered in dvsekhvalnov jose2go 1.5.0 thru 1.7.0 allowing an attacker to cause a Denial-of-Service (DoS) via crafted JSON WeEPSS 0.2%CVE-2026-11611MEDIUM389-ds-base: 389-ds-base: content sync plugin unbounded queue growth and race conditionsEPSS 0.2%CVE-2025-69198MEDIUMPterodactyl's improper resource locking allows raced queries to create more resources than allotedEPSS 0.2%CVE-2023-39328MEDIUMOpenjpeg: denail of service via crafted image fileEPSS 0.2%CVE-2024-32902HIGHRemote prevention of access to cellular service with no user interaction (for example, crashing the cellular radio service with a malformed EPSS 0.2%CVE-2025-6140MEDIUMspdlog pattern_formatter-inl.h scoped_padder resource consumptionEPSS 0.2%CVE-2024-26723HIGHlan966x: Fix crash when adding interface under a lagEPSS 0.2%CVE-2025-41226MEDIUMGuest Operations Denial-of-Service VulnerabilityEPSS 0.2%CVE-2025-31226MEDIUMA logic issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, tvOS 1EPSS 0.2%CVE-2026-86608HIGHWP Recipe Maker 9.8.0 - 10.8.1 - Unauthenticated DoS via Unbounded User Meta InsertionEPSS 0.2%CVE-2023-42941MEDIUMThe issue was addressed with improved checks. This issue is fixed in iOS 17.2 and iPadOS 17.2. An attacker in a privileged network position EPSS 0.2%CVE-2024-37535MEDIUMGNOME VTE before 0.76.3 allows an attacker to cause a denial of service (memory consumption) via a window resize escape sequence, a related EPSS 0.2%CVE-2025-44559MEDIUMAn issue in the Bluetooth Low Energy (BLE) stack of Realtek RTL8762E BLE SDK v1.4.0 allows attackers within Bluetooth range to cause a DeniaEPSS 0.2%CVE-2021-47238MEDIUMnet: ipv4: fix memory leak in ip_mc_add1_srcEPSS 0.2%CVE-2024-38384HIGHblk-cgroup: fix list corruption from reorder of WRITE ->lqueuedEPSS 0.2%CVE-2024-31146HIGHPCI device pass-through with shared resourcesEPSS 0.2%CVE-2025-30725MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.2%CVE-2024-31209MEDIUMOpenID Connect client Atom Exhaustion in provider configuration worker ets table locationEPSS 0.2%CVE-2026-82001MEDIUMAcrobat Reader | Uncontrolled Resource Consumption (CWE-400)EPSS 0.2%CVE-2024-22104MEDIUMOut-of-Bounds Write vulnerability in Jungo WinDriver before 12.5.1 allows local attackers to cause a Windows blue screen error and Denial ofEPSS 0.2%