Weaknesses of type CWE-400

2,995 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2021-3909MEDIUMInfinite open connection causes OctoRPKI to hang foreverEPSS 1.6%CVE-2020-6986HIGHIn all versions of Omron PLC CJ Series, an attacker can send a series of specific data packets within a short period, causing a service erroEPSS 1.6%CVE-2020-8293—A missing input validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows users to store unlimited data in workflow rules causingEPSS 1.6%CVE-2020-8246—Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 1EPSS 1.6%CVE-2021-24893—Stars Rating < 3.5.1 - Comments Denial of ServiceEPSS 1.6%CVE-2018-16487—A prototype pollution vulnerability was found in lodash <4.17.11 where the functions merge, mergeWith, and defaultsDeep can be tricked into EPSS 1.6%CVE-2026-23869HIGHA denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-parcel, react-serverEPSS 1.6%CVE-2023-23552HIGHBIG-IP Advanced WAF and ASM vulnerabilityEPSS 1.5%CVE-2024-20965MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 aEPSS 1.5%CVE-2023-39477HIGHInductive Automation Ignition ConditionRefresh Resource Exhaustion Denial-of-Service VulnerabilityEPSS 1.5%CVE-2020-26256MEDIUMDenial of service in fast-csvEPSS 1.5%CVE-2021-20298—A flaw was found in OpenEXR's B44Compressor. This flaw allows an attacker who can submit a crafted file to be processed by OpenEXR, to exhauEPSS 1.5%CVE-2021-40406HIGHA denial of service vulnerability exists in the cgiserver.cgi session creation functionality of reolink RLC-410W v3.0.0.136_20121102. A specEPSS 1.5%CVE-2019-1965HIGHCisco NX-OS Software Remote Management Memory Leak Denial of Service VulnerabilityEPSS 1.5%CVE-2022-36083MEDIUMJOSE vulnerable to resource exhaustion via specifically crafted JWEEPSS 1.5%CVE-2019-15593—GitLab 12.2.3 contains a security vulnerability that allows a user to affect the availability of the service through a Denial of Service attEPSS 1.5%CVE-2021-21235MEDIUMInfinite loop in parsing PNG files inEPSS 1.5%CVE-2019-12714MEDIUMCisco IC3000 Industrial Compute Gateway Denial of Service VulnerabilityEPSS 1.5%CVE-2024-53299MEDIUMApache Wicket: An attacker can intentionally trigger a memory leakEPSS 1.5%CVE-2024-24762HIGHpython-multipart vulnerable to content-type header Regular expression Denial of ServiceEPSS 1.5%