Weaknesses of type CWE-400

3,026 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2026-5316MEDIUMNothings stb stb_vorbis.c setup_free allocation of resourcesEPSS 0.7%CVE-2025-2833MEDIUMzhangyd-c OneBlog HTTP Header redosEPSS 0.7%CVE-2024-1014MEDIUMUncontrolled resource consumption vulnerability in SE-elektronic GmbH E-DDC3.3EPSS 0.7%CVE-2024-23265CRITICALA memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPaEPSS 0.7%CVE-2022-3818MEDIUMAn uncontrolled resource consumption issue when parsing URLs in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, aEPSS 0.7%CVE-2022-3510HIGHParsing issue in protobuf message-type extensionEPSS 0.7%CVE-2022-34335MEDIUMIBM Sterling Partner Engagement Manager denial of serviceEPSS 0.7%CVE-2025-47270HIGHnimiq-network-libp2p Uncontrolled Resource Consumption vulnerabilityEPSS 0.7%CVE-2024-20321HIGHA vulnerability in the External Border Gateway Protocol (eBGP) implementation of Cisco NX-OS Software could allow an unauthenticated, remoteEPSS 0.7%CVE-2022-23486HIGHlibp2p-rust denial of service vulnerability from lack of resource managementEPSS 0.7%CVE-2026-55685HIGHReact Router: Unauthenticated Denial of Service via Inefficient Route MatchingEPSS 0.7%CVE-2022-23487HIGHlibp2p denial of service vulnerability from lack of resource managementEPSS 0.7%CVE-2026-45031MEDIUMImageMagick: Policy Bypass in PSD decoderEPSS 0.7%CVE-2026-61554HIGHemp3r0r has an unauthenticated HTTP Polling DoSEPSS 0.7%CVE-2024-11043HIGHDenial of Service (DoS) via Large Payload in Board Name Field in invoke-ai/invokeaiEPSS 0.7%CVE-2024-12761HIGHDenial of Service in brycedrennan/imaginairyEPSS 0.7%CVE-2023-37481LOWFides Webserver Vulnerable to SVG Bomb File UploadsEPSS 0.7%CVE-2024-27874HIGHThis issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS 18. A remote attacker may be able to caEPSS 0.7%CVE-2022-31079MEDIUMKubeEdge Cloud Stream and Edge Stream DoS from large stream messageEPSS 0.7%CVE-2022-31078MEDIUMKubeEdge CloudCore Router memory exhaustionEPSS 0.7%