Weaknesses of type CWE-400

2,995 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2022-38371HIGHA vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (EPSS 1.4%CVE-2018-6346HIGHA potential denial-of-service issue in the Proxygen handling of invalid HTTP2 priority settings (specifically a circular dependency). This aEPSS 1.4%CVE-2018-6347HIGHAn issue in the Proxygen handling of HTTP2 parsing of headers/trailers can lead to a denial-of-service attack. This affects Proxygen prior tEPSS 1.4%CVE-2025-24126CRITICALAn input validation issue was addressed. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS VenEPSS 1.4%CVE-2023-3163LOWy_project RuoYi filterKeyword resource consumptionEPSS 1.4%CVE-2020-25630—A vulnerability was found in Moodle where the decompressed size of zip files was not checked against available user quota before unzipping tEPSS 1.4%CVE-2022-22543—SAP NetWeaver Application Server for ABAP (Kernel) and ABAP Platform (Kernel) - versions KERNEL 7.22, 8.04, 7.49, 7.53, 7.77, 7.81, 7.85, 7.EPSS 1.4%CVE-2019-19301HIGHA vulnerability has been identified in SCALANCE X200-4P IRT, SCALANCE X201-3P IRT, SCALANCE X201-3P IRT PRO, SCALANCE X202-2IRT, SCALANCE X2EPSS 1.4%CVE-2021-41119MEDIUMDoS vulnerabiliity in wire-server json parserEPSS 1.4%CVE-2019-10942—A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.5), SCALANCE X-200IRT sEPSS 1.4%CVE-2025-29954MEDIUMWindows Lightweight Directory Access Protocol (LDAP) Denial of Service VulnerabilityEPSS 1.4%CVE-2020-14384—A flaw was found in JBossWeb in versions before 7.5.31.Final-redhat-3. The fix for CVE-2020-13935 was incomplete in JBossWeb, leaving it vulEPSS 1.4%CVE-2023-39321—Panic when processing post-handshake message on QUIC connections in crypto/tlsEPSS 1.4%CVE-2020-11645MEDIUMGateManager Denial of Service VulnerabilityEPSS 1.3%CVE-2017-16021—uri-js is a module that tries to fully implement RFC 3986. One of these features is validating whether or not a supplied URL is valid or notEPSS 1.3%CVE-2016-10544—uws is a WebSocket server library. By sending a 256mb websocket message to a uws server instance with permessage-deflate enabled, there is aEPSS 1.3%CVE-2021-32722MEDIUMUncontrolled Resource Consumption in GlobalNewFilesEPSS 1.3%CVE-2021-3629—A flaw was found in Undertow. A potential security issue in flow control handling by the browser over http/2 may potentially cause overhead EPSS 1.3%CVE-2021-39171MEDIUMUnlimited transforms allowed for signed nodesEPSS 1.3%CVE-2019-0059HIGHJunos OS: The routing protocol process (rpd) may crash and generate core files upon receipt of specific valid BGP states from a peered host.EPSS 1.3%