Weaknesses of type CWE-400

2,994 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2023-22796—A regular expression based DoS vulnerability in Active Support <6.1.7.1 and <7.0.4.1. A specially crafted string passed to the underscore meEPSS 1.7%CVE-2020-8237—Prototype pollution in json-bigint npm package < 1.0.0 may lead to a denial-of-service (DoS) attack.EPSS 1.7%CVE-2019-0031HIGHJunos OS: jdhcpd daemon memory consumption Denial of Service when receiving specific IPv6 DHCP packets.EPSS 1.7%CVE-2019-13940MEDIUMA vulnerability has been identified in SIMATIC ET 200pro IM154-8 PN/DP CPU (All versions < V3.X.17), SIMATIC ET 200pro IM154-8F PN/DP CPU (AEPSS 1.7%CVE-2024-23952MEDIUMApache Superset: Allows for uncontrolled resource consumption via a ZIP bomb (version range fix for CVE-2023-46104)EPSS 1.7%CVE-2023-22792HIGHA regular expression based DoS vulnerability in Action Dispatch <6.0.6.1,< 6.1.7.1, and <7.0.4.1. Specially crafted cookies, in combination EPSS 1.7%CVE-2021-20237—An uncontrolled resource consumption (memory leak) flaw was found in ZeroMQ's src/xpub.cpp in versions before 4.3.3. This flaw allows a remoEPSS 1.7%CVE-2019-10162LOWA vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.10, 4.0.8 allowing an authorized user to cause the serveEPSS 1.7%CVE-2017-6043—A Resource Consumption issue was discovered in Trihedral VTScada Versions prior to 11.2.26. The client does not properly validate the input EPSS 1.7%CVE-2021-41167HIGHUnlimited requests in modern-asyncEPSS 1.7%CVE-2018-16469—The merge.recursive function in the merge package <1.2.1 can be tricked into adding or modifying properties of the Object prototype. These pEPSS 1.7%CVE-2021-3690—A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attackEPSS 1.7%CVE-2019-19281—A vulnerability has been identified in SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions >= V2.5 and < VEPSS 1.7%CVE-2021-29469MEDIUMPotential exponential regex in monitor modeEPSS 1.7%CVE-2021-31409HIGHServer session is not invalidated when logout() helper method of Authentication module is used in Vaadin 18-19EPSS 1.7%CVE-2023-46104MEDIUMApache Superset: Allows for uncontrolled resource consumption via a ZIP bombEPSS 1.7%CVE-2021-21391MEDIUMRegular expression Denial of Service in multiple packagesEPSS 1.7%CVE-2020-15783HIGHA vulnerability has been identified in SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions), SIMATIC TDC EPSS 1.7%CVE-2025-26677HIGHWindows Remote Desktop Gateway (RD Gateway) Denial of Service VulnerabilityEPSS 1.7%CVE-2017-16116—The string module is a module that provides extra string operations. The string module is vulnerable to regular expression denial of serviceEPSS 1.7%