Weaknesses of type CWE-400

2,995 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2020-3560HIGHCisco Aironet Access Points UDP Flooding Denial of Service VulnerabilityEPSS 1.4%CVE-2020-3563HIGHCisco Firepower Threat Defense Software TCP Flood Denial of Service VulnerabilityEPSS 1.4%CVE-2022-36049HIGHFlux2 Helm Controller denial of serviceEPSS 1.4%CVE-2025-53645HIGHZimbra Collaboration (ZCS) before 9.0.0 Patch 46, 10.0.x before 10.0.15, and 10.1.x before 10.1.9 is vulnerable to a denial of service condiEPSS 1.4%CVE-2023-0662HIGHDoS vulnerability when parsing multipart request bodyEPSS 1.4%CVE-2020-3559MEDIUMCisco Aironet Access Point Authentication Flood Denial of Service VulnerabilityEPSS 1.4%CVE-2021-29506MEDIUMNavigate endpoint is vulnerable to regex injection that may lead to Denial of Service.EPSS 1.4%CVE-2019-10923HIGHAn attacker with network access to an affected product may cause a denial of service condition by breaking the real-time synchronization (IREPSS 1.4%CVE-2025-49716HIGHWindows Netlogon Denial of Service VulnerabilityEPSS 1.4%CVE-2016-10539—negotiator is an HTTP content negotiator for Node.js and is used by many modules and frameworks including Express and Koa. The header for "AEPSS 1.4%CVE-2024-40634HIGHArgo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook EndpointEPSS 1.4%CVE-2021-22116—RabbitMQ all versions prior to 3.8.16 are prone to a denial of service vulnerability due to improper input validation in AMQP 1.0 client conEPSS 1.4%CVE-2022-38150MEDIUMIn Varnish Cache 7.0.0, 7.0.1, 7.0.2, and 7.1.0, it is possible to cause the Varnish Server to assert and automatically restart through forgEPSS 1.4%CVE-2022-21689HIGHDenial of Service in OnionshareEPSS 1.4%CVE-2023-50967HIGHlatchset jose through version 11 allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.EPSS 1.4%CVE-2021-43838MEDIUMRegular Expression Denial of Service (ReDoS) in jsx-slackEPSS 1.4%CVE-2021-20185—It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that messaging did not impose a character limit when sending messages,EPSS 1.4%CVE-2020-27782—A flaw was found in the Undertow AJP connector. Malicious requests and abrupt connection closes could be triggered by an attacker using querEPSS 1.4%CVE-2020-3571HIGHCisco Firepower 4110 ICMP Flood Denial of Service VulnerabilityEPSS 1.4%CVE-2023-25816MEDIUMnextcloud vulnerable to Uncontrolled Resource ConsumptionEPSS 1.4%