Weaknesses of type CWE-400

3,026 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2023-40703MEDIUMDenial of Service via specially crafted block fields in Mattermost BoardsEPSS 0.7%CVE-2022-31080MEDIUMKubeEdge Websocket Client in package Viaduct: DoS from large response messageEPSS 0.7%CVE-2025-0187HIGHDenial of Service (DoS) by Sending Large Filename at File Upload Endpoint in gradio-app/gradioEPSS 0.7%CVE-2023-40586HIGHgo package github.com/corazawaf/coraza is vulnerable to denial of serviceEPSS 0.7%CVE-2023-48268MEDIUMDenial of Service via Board Import Zip BombEPSS 0.7%CVE-2023-46131MEDIUMGrails® data binding causes JVM crash and/or DoS EPSS 0.7%CVE-2025-21614HIGHgo-git clients vulnerable to DoS via maliciously crafted Git server repliesEPSS 0.7%CVE-2021-22906—Nextcloud End-to-End Encryption before 1.5.3, 1.6.3 and 1.7.1 suffers from a denial of service vulnerability due to permitting any authenticEPSS 0.7%CVE-2023-3782MEDIUMDoS of the OkHttp client when using a BrotliInterceptor and surfing to a malicious web server, or when an attacker can perform MitM to inject a Brotli zip-bomb into an HTTP responseEPSS 0.7%CVE-2022-35241MEDIUMNGINX Instance Manager vulnerability CVE-2022-35241EPSS 0.7%CVE-2025-70327CRITICALTOTOLINK X5000R v9.1.0cu_2415_B20250515 contains an argument injection vulnerability in the setDiagnosisCfg handler of the /usr/sbin/lighttpEPSS 0.7%CVE-2026-44241HIGHMicronaut Framework: Unbounded formattersCache in TimeConverterRegistrar Allows Memory Exhaustion via Accept-Language HeaderEPSS 0.7%CVE-2025-4533MEDIUMJeecgBoot Document Library Upload zip unzipFile resource consumptionEPSS 0.7%CVE-2026-63448MEDIUMSuricata smb: some SMB flows can cause resource exhaustionEPSS 0.7%CVE-2023-28356HIGHA vulnerability has been identified where a maliciously crafted message containing a specific chain of characters can cause the chat to enteEPSS 0.7%CVE-2022-45044MEDIUMA vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V9.50), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 EPSS 0.7%CVE-2024-24781HIGHHima: Uncontrolled Resource Consumption in multiple productsEPSS 0.7%CVE-2024-31992MEDIUMMealie contains a DoS vulnerability in recipe importerEPSS 0.7%CVE-2026-5316MEDIUMNothings stb stb_vorbis.c setup_free allocation of resourcesEPSS 0.7%CVE-2026-46273HIGHibmveth: Disable GSO for packets with small MSSEPSS 0.7%