Weaknesses of type CWE-400

2,999 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2017-0938—Denial of Service attack in airMAX < 8.3.2 , airMAX < 6.0.7 and EdgeMAX < 1.9.7 allow attackers to use the Discovery Protocol in amplificatiEPSS 21.0%CVE-2025-67779HIGHIt was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attacEPSS 20.0%CVE-2024-31152MEDIUMThe LevelOne WBR-6012 router with firmware R0.40e6 is vulnerable to improper resource allocation within its web application, where a series EPSS 17.8%CVE-2019-14901HIGHA heap overflow flaw was found in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The vulnerabiliEPSS 16.9%CVE-2010-5107HIGHThe default configuration of OpenSSH through 6.1 enforces a fixed time limit between establishing a TCP connection and completing a login, wEPSS 16.5%CVE-2019-5737—In Node.js including 6.x before 6.17.0, 8.x before 8.15.1, 10.x before 10.15.2, and 11.x before 11.10.1, an attacker can cause a Denial of SEPSS 16.2%CVE-2026-34650HIGHAdobe Commerce | Uncontrolled Resource Consumption (CWE-400)EPSS 15.9%CVE-2021-35559MEDIUMVulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported versions that are afEPSS 15.9%CVE-2023-22512HIGHThis High severity DoS (Denial of Service) vulnerability was introduced in version 5.6.0 of Confluence Data Center and Server. With a CVSS SEPSS 15.4%CVE-2022-24713HIGHRegular expression denial of service in Rust's regex crateEPSS 14.5%CVE-2026-34649HIGHAdobe Commerce | Uncontrolled Resource Consumption (CWE-400)EPSS 14.4%CVE-2023-38180HIGH.NET and Visual Studio Denial of Service VulnerabilityEPSS 14.0%KEVCVE-2024-8182HIGHFlowise Denial of ServiceEPSS 13.9%CVE-2021-21348MEDIUMXStream is vulnerable to an attack using Regular Expression for a Denial of Service (ReDos)EPSS 13.8%CVE-2022-3094HIGHAn UPDATE message flood may cause named to exhaust all available memoryEPSS 13.2%CVE-2022-20624HIGHCisco NX-OS Software Cisco Fabric Services Over IP Denial of Service VulnerabilityEPSS 12.4%CVE-2018-16844MEDIUMnginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive CPU usage. This issEPSS 12.4%CVE-2024-6036HIGHDenial of Service in gaizhenbiao/chuanhuchatgptEPSS 10.9%CVE-2018-12121—Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Denial of Service with large HTTP headers: By using a combinationEPSS 10.2%CVE-2019-10952—Rockwell Automation CompactLogix 5370 Uncontrolled Resource ConsumptionEPSS 10.0%