Weaknesses of type CWE-400

3,026 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2023-4486HIGHUncontrolled Resource Consumption in Metasys and Facility ExplorerEPSS 0.8%CVE-2024-20344MEDIUMA vulnerability in system resource management in Cisco UCS 6400 and 6500 Series Fabric Interconnects that are in Intersight Managed Mode (IMEPSS 0.8%CVE-2026-27630HIGHTinyWeb vulnerable to Remote Denial of Service via Thread/Connection Exhaustion (Slowloris)EPSS 0.8%CVE-2026-42006MEDIUMAn attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomplete, only blocking onEPSS 0.8%CVE-2026-92596HIGHNodemailer before 9.1.0 Denial of Service via addressparserEPSS 0.8%CVE-2026-27633HIGHTinyWeb has Unbounded Content-Length Memory Exhaustion (DoS)EPSS 0.8%CVE-2026-47073HIGHUnbounded memory consumption in WebSocket client in hackneyEPSS 0.8%CVE-2025-5024HIGHGnome-remote-desktop: uncontrolled resource consumption due to malformed rdp pdusEPSS 0.8%CVE-2024-12074MEDIUMDenial of Service in automatic1111/stable-diffusion-webuiEPSS 0.8%CVE-2025-53012MEDIUMMaterialX's Lack of Import Depth Limit Leads to DoS (Denial-Of-Service) Via Stack ExhaustionEPSS 0.8%CVE-2024-21173MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.37 and prior anEPSS 0.8%CVE-2024-21130MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.37 aEPSS 0.8%CVE-2026-25949HIGHTraefik: TCP readTimeout bypass via STARTTLS on PostgresEPSS 0.8%CVE-2024-9409HIGHCWE-400: An Uncontrolled Resource Consumption vulnerability exists that could cause the device to become unresponsive resulting in communicaEPSS 0.8%CVE-2022-43572HIGHIndexing blockage via malformed data sent through S2S or HEC protocols in Splunk EnterpriseEPSS 0.8%CVE-2023-41173—AdGuard DNS before 2.2 allows remote attackers to cause a denial of service via malformed UDP packets.EPSS 0.8%CVE-2020-1625MEDIUMJunos OS: Kernel memory leak in virtual-memory due to interface flapsEPSS 0.8%CVE-2024-10466HIGHBy sending a specially crafted push message, a remote server could have hung the parent process, causing the browser to become unresponsive.EPSS 0.8%CVE-2026-79651HIGHKeycloak-services: keycloak-services: unauthenticated dos via unbounded locale cachingEPSS 0.8%CVE-2026-27857MEDIUMSending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands will result in client EPSS 0.8%