Weaknesses of type CWE-400

3,026 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2022-1468MEDIUMOn all versions of 17.0.x, 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x on F5 BIG-IP, an authenticated iControl REST user with at leasEPSS 0.9%CVE-2024-38809MEDIUMApplications that parse ETags from "If-Match" or "If-None-Match" request headers are vulnerable to DoS attack. Users of affected versions sEPSS 0.9%CVE-2021-22642HIGHOvarro TBox Uncontrolled Resource ConsumptionEPSS 0.9%CVE-2021-3912MEDIUMOctoRPKI crashes when processing GZIP bomb returned via malicious repositoryEPSS 0.9%CVE-2024-20996MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.37 and prior anEPSS 0.9%CVE-2024-21142MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected aEPSS 0.9%CVE-2024-23259MEDIUMThe issue was addressed with improved checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14EPSS 0.9%CVE-2024-21127MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.37 and priEPSS 0.9%CVE-2026-40983HIGHMicrometer gRPC server instrumentation DoS vulnerabilityEPSS 0.8%CVE-2026-44250HIGHNetty: Memory Exhaustion in RedisArrayAggregator due to Deeply Nested ArraysEPSS 0.8%CVE-2026-50011HIGHNetty has unbounded pre-allocation in RedisArrayAggregator from RESP array lengthEPSS 0.8%CVE-2026-44890HIGHNetty has Unbounded Direct Memory Consumption in its RedisDecoderEPSS 0.8%CVE-2018-0471—Cisco IOS XE Software Cisco Discovery Protocol Memory Leak VulnerabilityEPSS 0.8%CVE-2026-54772HIGHCoreWCF: Pre-authentication infinite-loop CPU exhaustion in CoreWCF net.tcp / net.pipe / net.uds framing handshakeEPSS 0.8%CVE-2022-43564MEDIUMDenial of Service in Splunk Enterprise through search macrosEPSS 0.8%CVE-2024-5013HIGHWhatsUp Gold InstallController Denial-of-Service VulnerabilityEPSS 0.8%CVE-2026-42579HIGHNetty: DNS Codec Input Validation Bypass in Netty (Encoder + Decoder)EPSS 0.8%CVE-2024-32972HIGHgo-ethereum denial of service via malicious p2p messageEPSS 0.8%CVE-2024-49129HIGHWindows Remote Desktop Gateway (RD Gateway) Denial of Service VulnerabilityEPSS 0.8%CVE-2020-9059—Z-Wave devices based on Silicon Labs 500 series chipsets using S0 authentication are susceptible to uncontrolled resource consumption leadinEPSS 0.8%