Weaknesses of type CWE-400

3,026 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2023-30769CRITICALRab13s ExploitEPSS 0.9%CVE-2021-22100—In cloud foundry CAPI versions prior to 1.122, a denial-of-service attack in which a developer can push a service broker that (accidentally EPSS 0.9%CVE-2025-21575MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 8.0.0-8.0.4EPSS 0.9%CVE-2022-43238MEDIUMLibde265 v1.0.8 was discovered to contain an unknown crash via ff_hevc_put_hevc_qpel_h_3_v_3_sse in sse-motion.cc. This vulnerability allowsEPSS 0.9%CVE-2023-20883HIGHIn Spring Boot versions 3.0.0 - 3.0.6, 2.7.0 - 2.7.11, 2.6.0 - 2.6.14, 2.5.0 - 2.5.14 and older unsupported versions, there is potential forEPSS 0.9%CVE-2023-23631MEDIUMHAMT Decoding Panics in github.com/ipfs/go-unixfsnodeEPSS 0.9%CVE-2023-2798HIGHDenial of service in HtmlUnitEPSS 0.9%CVE-2022-1982MEDIUMA crafted SVG attachment can crash a Mattermost serverEPSS 0.9%CVE-2017-2681HIGHSpecially crafted PROFINET DCP packets sent on a local Ethernet segment (Layer 2) to an affected product could cause a denial of service conEPSS 0.9%CVE-2022-41952MEDIUMUncontrolled Resource Consumption in Matrix Synapse EPSS 0.9%CVE-2023-34872MEDIUMA vulnerability in Outline.cc for Poppler prior to 23.06.0 allows a remote attacker to cause a Denial of Service (DoS) (crash) via a craftedEPSS 0.9%CVE-2022-23024—On BIG-IP AFM version 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.2, and all versions of 13.1.x, when the IPsec applicaEPSS 0.9%CVE-2025-7070MEDIUMIROAD Dashcam Q9 MFA Pairing Request allocation of resourcesEPSS 0.9%CVE-2022-26372HIGHOn F5 BIG-IP 15.1.x versions prior to 15.1.0.2, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1EPSS 0.9%CVE-2023-2990—Fortra Globalscape Administration Server Denial of ServiceEPSS 0.9%CVE-2026-75632HIGHCAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)EPSS 0.9%CVE-2026-48439HIGHCAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)EPSS 0.9%CVE-2026-34713HIGHCAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)EPSS 0.9%CVE-2026-34665HIGHCAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)EPSS 0.9%CVE-2026-34651HIGHAdobe Commerce | Uncontrolled Resource Consumption (CWE-400)EPSS 0.9%