Weaknesses of type CWE-400

3,026 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2022-46399HIGHThe Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) is unresponsive with ConReqTimeoutZerEPSS 0.7%CVE-2022-33203HIGHBIG-IP APM and F5 SSL Orchestrator vulnerability CVE-2022-33203EPSS 0.7%CVE-2024-25398HIGHIn Srelay (the SOCKS proxy and Relay) v.0.4.8p3, a specially crafted network payload can trigger a denial of service condition and disrupt tEPSS 0.7%CVE-2022-35236HIGHHTTP2 profile vulnerability CVE-2022-35236EPSS 0.7%CVE-2025-8262MEDIUMyarnpkg Yarn hosted-git-resolver.js explodeHostedGitFragment redosEPSS 0.7%CVE-2019-0038MEDIUMSRX Series: Crafted packets destined to fxp0 management interface on SRX340/SRX345 devices can lead to DoSEPSS 0.7%CVE-2025-49763HIGHApache Traffic Server: Remote DoS via memory exhaustion in ESI PluginEPSS 0.7%CVE-2025-4215LOWgorhill uBlock Origin UI 1p-filters.js currentStateChanged redosEPSS 0.7%CVE-2026-58210HIGHNATS Server: MQTT partial CONNECT packets can exhaust pre-auth memoryEPSS 0.7%CVE-2020-26652—An issue was discovered in function nl80211_send_chandef in rtl8812au v5.6.4.2 allows attackers to cause a denial of service.EPSS 0.7%CVE-2026-6607MEDIUMlm-sys fastchat Worker API Endpoint api_generate resource consumptionEPSS 0.7%CVE-2026-66144HIGHApache Neethi: Remote PolicyReference fetch lacks resource boundsEPSS 0.7%CVE-2026-50645HIGHApache CXF: No restriction on attachment headers per messageEPSS 0.7%CVE-2026-66142HIGHApache Neethi: Uncontrolled recursion in policy processingEPSS 0.7%CVE-2026-59173HIGHApache Traffic Server: DoS vulnerability in HTTP/2 via stalled flow-control conditionsEPSS 0.7%CVE-2026-66299HIGHApache Tomcat: DoS via WebSocket chat exampleEPSS 0.7%CVE-2026-42402HIGHApache Neethi: Policy Normalization Unbounded Resource Allocation DoSEPSS 0.7%CVE-2026-24012HIGHApache IoTDB: Denial of Service via Resource Exhaustion in Aggregation QueryEPSS 0.7%CVE-2022-28229HIGHThe hash functionality in userver before 42059b6319661583b3080cab9b595d4f8ac48128 allows attackers to cause a denial of service via crafted EPSS 0.7%CVE-2024-57519HIGHAn issue in Open5GS v.2.7.2 allows a remote attacker to cause a denial of service via the ogs_dbi_auth_info function in lib/dbi/subscriptionEPSS 0.7%