Weaknesses of type CWE-400

3,013 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2021-1266MEDIUMCisco Managed Services Accelerator Denial of Service VulnerabilityEPSS 1.1%CVE-2026-49799MEDIUMWindows Local Security Authority Subsystem Service (LSASS) Denial of Service VulnerabilityEPSS 1.1%CVE-2022-29177MEDIUMDoS via malicious p2p message in Go-EthereumEPSS 1.1%CVE-2026-21637MEDIUMA flaw in Node.js TLS error handling allows remote attackers to crash or exhaust resources of a TLS server when `pskCallback` or `ALPNCallbaEPSS 1.1%CVE-2023-34104HIGHRegex Injection via Doctype EntitiesEPSS 1.1%CVE-2022-31803MEDIUMCODESYS Gateway Server V2 prone to Denial of Service AttackEPSS 1.1%CVE-2022-29167HIGHReDoS vulnerability in header parsing in hawkEPSS 1.1%CVE-2022-48748HIGHnet: bridge: vlan: fix memory leak in __allowed_ingressEPSS 1.1%CVE-2024-27812HIGHA logic issue was addressed with improved file handling. This issue is fixed in visionOS 1.2. Processing web content may lead to a denial-ofEPSS 1.1%CVE-2023-31409MEDIUMUncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 112252EPSS 1.1%CVE-2021-31405HIGHRegular expression denial of service (ReDoS) in EmailField component in Vaadin 14 and 15-17EPSS 1.1%CVE-2017-16111—The content module is a module to parse HTTP Content-* headers. It is used by the hapijs framework to provide this functionality. The moduleEPSS 1.1%CVE-2022-39271HIGHTraefik HTTP/2 connections management could cause a denial of serviceEPSS 1.1%CVE-2023-20863MEDIUMIn spring framework versions prior to 5.2.24 release+ ,5.3.27+ and 6.0.8+ , it is possible for a user to provide a specially crafted SpEL exEPSS 1.1%CVE-2022-21155HIGHFernhill SCADA Uncontrolled Resource ConsumptionEPSS 1.1%CVE-2023-40591HIGHDenial of service via malicious p2p message in go-ethereumEPSS 1.1%CVE-2023-28626MEDIUMQuadratic runtime when parsing Markdown in comrakEPSS 1.1%CVE-2024-20962MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 aEPSS 1.1%CVE-2023-23447HIGHUncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 112252EPSS 1.1%CVE-2023-43646HIGHInefficient Regular Expression Complexity in get-func-nameEPSS 1.1%