Weaknesses of type CWE-400

3,041 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2026-87279MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.2%CVE-2026-47044MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.2%CVE-2026-34281MEDIUMVulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11.4. Easily EPSS 0.2%CVE-2025-70347MEDIUMAn issue in mquickjs before commit 74b7e (2026-01-15) allows a local attacker to cause a denial of service via a crafted file to the get_mblEPSS 0.2%CVE-2026-47022LOWVulnerability in the GoldenGate Stream Analytics product of Oracle GoldenGate (component: Security). The supported version that is affecteEPSS 0.1%CVE-2024-54192MEDIUMAn issue inTcpreplay v4.5.1 allows a local attacker to cause a denial of service via a crafted file to the tcpedit_dlt_getplugin function atEPSS 0.1%CVE-2025-53068MEDIUMVulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exEPSS 0.1%CVE-2026-6844MEDIUMBinutils: binutils: denial of service vulnerabilities in readelf via crafted elf filesEPSS 0.1%CVE-2025-9092LOWHybrid Module Deployment in Multi-JVM Environments Leading to Resource ExhaustionEPSS 0.1%CVE-2025-66861LOWAn issue was discovered in function d_unqualified_name in file cp-demangle.c in BinUtils 2.26 allowing attackers to cause a denial of servicEPSS 0.1%CVE-2026-93587MEDIUMImageMagick before 7.1.2-31 Policy Bypass via PCD decoderEPSS 0.1%CVE-2025-52636LOWHCL AION is affected by a improper handling of uploads files SizeEPSS 0.1%CVE-2022-38687MEDIUMIn messaging service, there is a missing permission check. This could lead to local denial of service in messaging service with no additionaEPSS 0.1%CVE-2025-37139MEDIUMVulnerability in AOS firmware allows for Authenticated Local malicious actor to Permanently Disable BootEPSS 0.1%CVE-2026-20602MEDIUMThe issue was addressed with improved handling of caches. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3EPSS 0.1%CVE-2026-10695MEDIUMIBM® Db2® is vulnerable to a denial of service when running non fenced federated queriesEPSS 0.1%CVE-2026-62465MEDIUMVulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affeEPSS 0.1%CVE-2025-22242MEDIUMCVE-2025-22242 salt advisoryEPSS 0.1%CVE-2026-81880MEDIUMradare2: Uncontrolled resource consumption in radare2 PEF loaderEPSS 0.1%CVE-2025-6075LOWQuadratic complexity in os.path.expandvars() with user-controlled templateEPSS 0.1%