Weaknesses of type CWE-400

3,000 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2019-12658HIGHCisco IOS XE Software Filesystem Exhaustion Denial of Service VulnerabilityEPSS 2.0%CVE-2025-21330HIGHWindows Remote Desktop Services Denial of Service VulnerabilityEPSS 2.0%CVE-2023-37379—Apache Airflow: Exposure of sensitive connection information, DOS and SSRF on "test connection" featureEPSS 2.0%CVE-2020-36320HIGHRegular expression Denial of Service (ReDoS) in EmailValidator class in Vaadin 7EPSS 2.0%CVE-2026-28318HIGHSolarWinds Serv-U Unauthenticated Denial of Service VulnerabilityEPSS 1.9%KEVCVE-2021-21296LOWDenial-of-service in FleetEPSS 1.9%CVE-2025-21389HIGHWindows Universal Plug and Play (UPnP) Device Host Denial of Service VulnerabilityEPSS 1.9%CVE-2024-54677MEDIUMApache Tomcat: DoS in examples web applicationEPSS 1.9%CVE-2023-28217HIGHWindows Network Address Translation (NAT) Denial of Service VulnerabilityEPSS 1.9%CVE-2026-46522HIGHImageMagick: Infinite Loop in the MIFF decoder can lead to CPU exhaustionEPSS 1.9%CVE-2019-5472—An authorization issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 that prevented owners and maintainer to delete epEPSS 1.9%CVE-2024-2757HIGHPHP mb_encode_mimeheader runs endlessly for some inputsEPSS 1.9%CVE-2017-16118—The forwarded module is used by the Express.js framework to handle the X-Forwarded-For header. It is vulnerable to a regular expression deniEPSS 1.9%CVE-2020-3196HIGHCisco Adaptive Security Appliance Software and Firepower Threat Defense Software SSL/TLS Denial of Service VulnerabilityEPSS 1.9%CVE-2020-3195HIGHCisco Adaptive Security Appliance Software and Firepower Threat Defense Software OSPF Packets Processing Memory Leak VulnerabilityEPSS 1.9%CVE-2021-43843MEDIUMInsufficient patch for Regular Expression Denial of Service (ReDoS) to jsx-slack v4.5.1EPSS 1.9%CVE-2017-16025—Nes is a websocket extension library for hapi. Hapi is a webserver framework. Versions below and including 6.4.0 have a denial of service vuEPSS 1.9%CVE-2021-39229HIGHRegular expression deinal of service in appriseEPSS 1.9%CVE-2023-24534HIGHExcessive memory allocation in net/http and net/textprotoEPSS 1.9%CVE-2020-12516HIGHWAGO: PLC families 750-88x and 750-352 prone to DoS attackEPSS 1.9%