Weaknesses of type CWE-400

3,026 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2026-86513MEDIUMjava-json-tools jackson-coreutils JSON Pointer parser TreePointer.java TreePointer.tokensFromInput allocation of resourcesEPSS 0.7%CVE-2026-93310MEDIUMO-RAN-SC SMO OAM VES Collector allocation of resourcesEPSS 0.7%CVE-2026-92220MEDIUMvllm-project vLLM MoRIIO Acknowledgement moriio_connector.py MoRIIOWrapper._handle_release_message resource consumptionEPSS 0.7%CVE-2026-86511MEDIUMjava-json-tools jackson-coreutils JacksonUtils.java BigDecimal.toPlainString resource consumptionEPSS 0.7%CVE-2026-21720HIGHUnauthenticated DoS: avatar cache leaks goroutines when /avatar/:hash requests time outEPSS 0.7%CVE-2026-86319MEDIUMjava-json-tools json-patch Patch Operation JsonPatch.java JsonPatch.apply resource consumptionEPSS 0.7%CVE-2026-90582MEDIUMevanchiu serverless-todo API Todo Endpoint index.js saveTodos resource consumptionEPSS 0.7%CVE-2023-41151HIGHAn uncaught exception issue discovered in Softing OPC UA C++ SDK before 6.30 for Windows operating system may cause the application to crashEPSS 0.7%CVE-2023-39248HIGH Dell OS10 Networking Switches running 10.5.2.x and above contain an Uncontrolled Resource Consumption (Denial of Service) vulnerability, whEPSS 0.7%CVE-2026-26999HIGHTraefik: tcp router clears read deadlines before tls forwarding, enabling stalled handshakes (slowloris doS)EPSS 0.7%CVE-2026-45768HIGHSuricata ldap: unbounded responses per transaction can lead to resource exhaustionEPSS 0.7%CVE-2026-57227HIGHSuricata mqtt: unbounded resource consumption from repeated pubrec and pubrel messagesEPSS 0.7%CVE-2026-47077HIGHUnbounded body accumulation in HTTP/3 response loop in hackneyEPSS 0.7%CVE-2026-59933HIGHPhpSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustionEPSS 0.7%CVE-2024-24750MEDIUMBackpressure request ignored in fetch() in UndiciEPSS 0.7%CVE-2026-59932HIGHPhpSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustionEPSS 0.7%CVE-2026-47071HIGHSOCKS5 TLS upgrade ignores caller timeout in hackneyEPSS 0.7%CVE-2023-50707CRITICALUncontrolled Resource Consumption in EFACEC BCU 500EPSS 0.7%CVE-2024-57655HIGHAn issue in the dfe_n_in_order component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via craEPSS 0.7%CVE-2023-36818MEDIUMDenial of service via User Custom Sidebar Section Unlimited Link Creation in discourseEPSS 0.7%