Weaknesses of type CWE-400

3,026 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2022-22145—CAMS for HIS Log Server contained in the following Yokogawa Electric products is vulnerable to uncontrolled resource consumption. CENTUM CS EPSS 0.8%CVE-2023-49800HIGHDenial of service by abusing `fetchOptions.retry` in nuxt-api-partyEPSS 0.8%CVE-2023-5625MEDIUMPython-eventlet: patch regression for cve-2021-21419 in some red hat buildsEPSS 0.8%CVE-2026-42001HIGHInsufficient Validation of Autoprimary SOA QueriesEPSS 0.8%CVE-2016-10524—i18n-node-angular is a module used to interact between i18n and angular without using additional resources. A REST API endpoint that is usedEPSS 0.8%CVE-2026-42403HIGHApache Neethi: Circular Policy Reference Infinite LoopEPSS 0.8%CVE-2024-45626MEDIUMApache James: denial of service through JMAP HTML to text conversionEPSS 0.8%CVE-2022-31074MEDIUMKubeEdge Cloud AdmissionController component DoSEPSS 0.8%CVE-2023-23296MEDIUMKorenix JetWave 4200 Series 1.3.0 and JetWave 3200 Series 1.6.0 are vulnerable to Denial of Service via /goform/formDefault.EPSS 0.8%CVE-2023-27483MEDIUMfieldpath's Paved.SetValue allows growing arrays up to arbitrary sizes in crossplane-runtimeEPSS 0.8%CVE-2023-0384MEDIUMUncontrolled Resource Consuption in M-Files ServerEPSS 0.8%CVE-2022-23591HIGHStack overflow in TensorflowEPSS 0.8%CVE-2024-39895MEDIUMDirectus GraphQL Field Duplication Denial of Service (DoS)EPSS 0.8%CVE-2026-96541HIGHGnome-remote-desktop: gnome-remote-desktop: unauthenticated rdp sockets lack a handshake deadlineEPSS 0.8%CVE-2021-0215MEDIUMJunos OS: EX Series, QFX Series, SRX Branch Series, MX Series: Memory leak in packet forwarding engine due to 802.1X authenticator port interface flapsEPSS 0.8%CVE-2025-30704MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services). Supported versions that are affected arEPSS 0.8%CVE-2022-21653MEDIUMHash collision in typelevel jawnEPSS 0.8%CVE-2026-7790HIGHUnbounded chunk-size hex digits in cowlib cause quadratic CPU and memory DoSEPSS 0.8%CVE-2021-38463HIGHAUVESY VersiondogEPSS 0.8%CVE-2026-73507HIGHNetty: Denial of Service in XmlFrameDecoder via CPU ExhaustionEPSS 0.8%