Weaknesses of type CWE-400

3,039 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2026-71870MEDIUMpypdf: Possible large memory usage for large /ToUnicode streamsEPSS 0.2%CVE-2025-29477MEDIUMAn issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the function consume_event.EPSS 0.2%CVE-2026-82735MEDIUMMatch regex runs on over-length input in Ash.Type.String, enabling regex denial of serviceEPSS 0.2%CVE-2023-20911HIGHIn addPermission of PermissionManagerServiceImpl.java , there is a possible failure to persist permission settings due to resource exhaustioEPSS 0.2%CVE-2026-82742MEDIUMAsh.Filter.Runtime materializes a combinatorial cross-product over to-many relationships, exhausting memoryEPSS 0.2%CVE-2026-82743LOWAsh.Actions.Read.AsyncLimiter busy-spins a scheduler while awaiting slow async readsEPSS 0.2%CVE-2026-81869MEDIUMOpenTelemetry-Go: UTF-8 replacement rune bypasses attribute length truncationEPSS 0.2%CVE-2025-59529MEDIUMsimple protocol server ignores accepts unlimited connections and logs failures without limitEPSS 0.2%CVE-2026-48155MEDIUMpypdf: Possible large memory usage for large offsets for layout mode textEPSS 0.2%CVE-2026-27576MEDIUMOpenClaw: ACP prompt-size checks missing in local stdio bridge could reduce responsiveness with very large inputsEPSS 0.2%CVE-2026-43653MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS EPSS 0.2%CVE-2025-40802LOWA vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions). The affected device may be susceptible to resourceEPSS 0.2%CVE-2019-25724HIGHDräger Infinity M300 VG2.x Network-Based Denial of ServiceEPSS 0.2%CVE-2026-71642MEDIUMAn issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denEPSS 0.2%CVE-2023-25179MEDIUMUncontrolled resource consumption in the Intel(R) Unite(R) android application before Release 17 may allow an authenticated user to potentiaEPSS 0.2%CVE-2026-49461MEDIUMpypdf: Possible large memory usage for form XObjects during text extractionEPSS 0.2%CVE-2022-46645MEDIUMUncontrolled resource consumption in the Intel(R) Smart Campus Android application before version 9.9 may allow an authenticated user to potEPSS 0.2%CVE-2022-41801MEDIUMUncontrolled resource consumption in the Intel(R) Connect M Android application before version 1.82 may allow an authenticated user to potenEPSS 0.2%CVE-2026-60747MEDIUMVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affeEPSS 0.2%CVE-2024-57673MEDIUMAn issue in floodlight v1.2 allows a local attacker to cause a denial of service via the Topology Manager module and Linkdiscovery moduleEPSS 0.2%