Weaknesses of type CWE-400

2,995 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2017-16113—The parsejson module is vulnerable to regular expression denial of service when untrusted user input is passed into it to be parsed.EPSS 1.5%CVE-2020-3132MEDIUMCisco Email Security Appliance Shortened URL Denial of Service VulnerabilityEPSS 1.5%CVE-2022-29243MEDIUMImproper input-size validation on the user new session name in Nextcloud ServerEPSS 1.5%CVE-2022-44571—There is a denial of service vulnerability in the Content-Disposition parsingcomponent of Rack fixed in 2.0.9.2, 2.1.4.2, 2.2.4.1, 3.0.0.1. EPSS 1.5%CVE-2021-21369MEDIUMPotential DoS in Besu HTTP JSON-RPC APIEPSS 1.5%CVE-2017-16115—The timespan module is vulnerable to regular expression denial of service. Given 50k characters of untrusted user input it will block the evEPSS 1.5%CVE-2021-1378MEDIUMCisco StarOS Denial of Service VulnerabilityEPSS 1.5%CVE-2019-13926—A vulnerability has been identified in SCALANCE S602 (All versions >= V3.0 and < V4.1), SCALANCE S612 (All versions >= V3.0 and < V4.1), SCAEPSS 1.5%CVE-2025-25293HIGHruby-saml vulnerable to Remote Denial of Service (DoS) with compressed SAML responsesEPSS 1.5%CVE-2021-47295HIGHnet: sched: fix memory leak in tcindex_partial_destroy_workEPSS 1.5%CVE-2020-8136—Prototype pollution vulnerability in fastify-multipart < 1.0.5 allows an attacker to crash fastify applications parsing multipart requests bEPSS 1.5%CVE-2024-39908MEDIUMDenial of service in REXMLEPSS 1.5%CVE-2020-14522HIGHSofting Industrial Automation OPCEPSS 1.5%CVE-2020-29490HIGHDell EMC Unity, Unity XT, and UnityVSA versions prior to 5.0.4.0.5.012 contain a Denial of Service vulnerability on NAS Servers with NFS expEPSS 1.5%CVE-2018-16486—A prototype pollution vulnerability was found in defaults-deep <=0.2.4 that would allow a malicious user to inject properties onto Object.prEPSS 1.5%CVE-2024-4068HIGHMemory Exhaustion in bracesEPSS 1.5%CVE-2018-6335HIGHA Malformed h2 frame can cause 'std::out_of_range' exception when parsing priority meta data. This behavior can lead to denial-of-service. TEPSS 1.5%CVE-2020-27295—The affected product has uncontrolled resource consumption issues, which may allow an attacker to cause a denial-of-service condition on theEPSS 1.5%CVE-2021-21236MEDIUMRegular Expression Denial of Service in CairoSVGEPSS 1.5%CVE-2019-13946HIGHProfinet-IO (PNIO) stack versions prior V06.00 do not properly limit internal resource allocation when multiple legitimate diagnostic packagEPSS 1.5%