Weaknesses of type CWE-400

3,026 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2022-39294HIGH(DoS) Denial of Service from unchecked request length in conduit-hyperEPSS 0.7%CVE-2021-36395HIGHIn Moodle, the file repository's URL parsing required additional recursion handling to mitigate the risk of recursion denial of service.EPSS 0.7%CVE-2026-57819HIGHApache CXF: No default restriction on the amount of form parameters per messageEPSS 0.7%CVE-2026-33610MEDIUMPossible file descriptor exhaustion in forward-dnsupdateEPSS 0.7%CVE-2021-3908MEDIUMInfinite certificate chain depth results in OctoRPKI running foreverEPSS 0.7%CVE-2024-20351HIGHCisco Firepower Threat Defense Software Snort Firewall Denial of Service VulnerabilityEPSS 0.7%CVE-2026-58182HIGHApache Traffic Server: ts_lua plugin has initialization and resource-handling errorsEPSS 0.7%CVE-2022-42929MEDIUMIf a website called `window.print()` in a particular way, it could cause a denial of service of the browser, which may persist beyond browseEPSS 0.7%CVE-2026-73634HIGHApache Struts: Unbounded read of a Content Security Policy violation reportEPSS 0.7%CVE-2024-11033MEDIUMDenial of Service (DoS) in binary-husky/gpt_academicEPSS 0.7%CVE-2023-49290MEDIUMMalicious parameters can cause a denial of service in lestrrat-go/jwxEPSS 0.7%CVE-2026-8769MEDIUMvercel ai provider-utils response-handler.ts createJsonErrorResponseHandler resource consumptionEPSS 0.7%CVE-2026-44891HIGHNetty: Denial of Service via Unbounded Headers in StompSubframeDecoderEPSS 0.7%CVE-2023-25774HIGHA denial-of-service vulnerability exists in the vpnserver ConnectionAccept() functionality of SoftEther VPN 5.02. A set of specially craftedEPSS 0.7%CVE-2026-34045HIGHPodman Desktop WebView Server ExposedEPSS 0.7%CVE-2026-59843MEDIUMLibssh: libssh: denial of service via zero advertised channel packet sizeEPSS 0.7%CVE-2024-38828MEDIUMCVE-2024-38828: DoS via Spring MVC controller method with byte[] parameterEPSS 0.7%CVE-2026-90584MEDIUMTooTallNate Java-WebSocket Fragmentation Draft_6455.java processFrameContinuousAndNonFin allocation of resourcesEPSS 0.7%CVE-2026-92114MEDIUMa2ui-project a2ui Basic Catalog safe_regex.ts redosEPSS 0.7%CVE-2023-40703MEDIUMDenial of Service via specially crafted block fields in Mattermost BoardsEPSS 0.7%