Weaknesses of type CWE-400

3,041 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2026-22003MEDIUMVulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions tEPSS 0.1%CVE-2026-18822MEDIUMVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.1%CVE-2026-0049MEDIUMIn onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhaustion. This could lead EPSS 0.1%CVE-2026-19653MEDIUMVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.1%CVE-2024-49740MEDIUMIn multiple locations, there is a possible crash loop due to resource exhaustion. This could lead to local denial of service with no additioEPSS 0.1%CVE-2025-48590MEDIUMIn verifyAndGetBypass of AppOpsService.java, there is a possible method for a malicious app to prevent dialing emergency services under limiEPSS 0.1%CVE-2024-0026MEDIUMIn multiple functions of SnoozeHelper.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to EPSS 0.1%CVE-2025-48584MEDIUMIn multiple functions of NotificationManagerService.java, there is a possible way to bypass the per-package channel limits causing resource EPSS 0.1%CVE-2022-38674MEDIUMIn wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.EPSS 0.1%CVE-2025-26423MEDIUMIn validateIpConfiguration of WifiConfigurationUtil.java, there is a possible way to trigger a permanent DoS due to a missing bounds check. EPSS 0.1%CVE-2023-21090MEDIUMIn parseUsesPermission of ParsingPackageUtils.java, there is a possible boot loop due to resource exhaustion. This could lead to local deniaEPSS 0.1%CVE-2018-9447MEDIUMIn onCreate of EmergencyCallbackModeExitDialog.java, there is a possible way to crash the emergency callback mode due to a missing null checEPSS 0.1%CVE-2022-47370MEDIUMIn wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.EPSS 0.1%CVE-2023-21033MEDIUMIn addNetwork of WifiManager.java, there is a possible way to trigger a persistent DoS due to resource exhaustion. This could lead to local EPSS 0.1%CVE-2022-38677MEDIUMIn cell service, there is a missing permission check. This could lead to local denial of service in cell service with no additional executioEPSS 0.1%CVE-2026-28596MEDIUMIn parseInterventionFromXml of GameManagerService.java, there is a possible permanent denial of service due to resource exhaustion. This couEPSS 0.1%CVE-2026-28617MEDIUMIn add of WifiNetworkSuggestionsManager.java, there is a possible persistent DOS due to resource exhaustion. This could lead to local denialEPSS 0.1%CVE-2025-48603MEDIUMIn InputMethodInfo of InputMethodInfo.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to lEPSS 0.1%CVE-2025-48576MEDIUMIn updateNotificationChannelGroupFromPrivilegedListener of NotificationManagerService.java, there is a possible permanent denial of service EPSS 0.1%CVE-2025-26463MEDIUMIn allowPackageAccess of multiple files, resource exhaustion is possible when repeatedly adding allowed packages. This could lead to a localEPSS 0.1%