Weaknesses of type CWE-400

3,026 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2026-73633HIGHApache Struts: Unbounded read of a JSON request bodyEPSS 0.7%CVE-2023-38498MEDIUMDiscourse vulnerable to DoS via defer queueEPSS 0.7%CVE-2026-84553HIGHA resource exhaustion issue was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, mEPSS 0.7%CVE-2023-37463MEDIUMQuadratic complexity bugs may lead to a denial of serviceEPSS 0.7%CVE-2026-25771MEDIUMWazuh Vulnerable to Denial of Service via Synchronous I/O Blocking in Asynchronous Authentication MiddlewareEPSS 0.7%CVE-2020-15101LOWNested directory structure can lead to Uncontrolled Resource Consumption in freewvsEPSS 0.7%CVE-2024-23744HIGHAn issue was discovered in Mbed TLS 3.5.1. There is persistent handshake denial if a client sends a TLS 1.3 ClientHello without extensions.EPSS 0.7%CVE-2021-43933MEDIUMICSA-22-109-03 FANUC ROBOGUIDE Simulation PlatformEPSS 0.7%CVE-2023-29153MEDIUMUncontrolled resource consumption for some Intel(R) SPS firmware before version SPS_E5_06.01.04.002.0 may allow a privileged user to potentiEPSS 0.7%CVE-2026-4410MEDIUMIBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a denial of serviceEPSS 0.7%CVE-2025-59043HIGHOpenBao vulnerable to denial of service via malicious JSON request processingEPSS 0.7%CVE-2020-1702—A malicious container image can consume an unbounded amount of memory when being pulled to a container runtime host, such as Red Hat EnterprEPSS 0.7%CVE-2023-28440LOWDenial of service via admin theme import route in DiscourseEPSS 0.7%CVE-2026-47707MEDIUMStrawberry GraphQL's Bypass of MaxAliasesLimiter via Fragment Spreads leading to GraphQL Alias AmplificationEPSS 0.7%CVE-2024-25269HIGHlibheif <= 1.17.6 contains a memory leak in the function JpegEncoder::Encode. This flaw allows an attacker to cause a denial of service attaEPSS 0.7%CVE-2025-29907HIGHjsPDF Bypass Regular Expression Denial of Service (ReDoS)EPSS 0.7%CVE-2026-50750HIGHApache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: Pre-authentication OpenWire DoS following fix for CVE-2026-49270EPSS 0.7%CVE-2023-37480LOWFides Webserver Vulnerable to Zip Bomb File UploadsEPSS 0.7%CVE-2023-43810HIGHopentelemetry-instrumentation Denial of Service vulnerability due to unbound cardinality metricsEPSS 0.7%CVE-2025-53114HIGHCometD has acknowledgement extension out of memoryEPSS 0.7%