Weaknesses of type CWE-400

3,026 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2026-49485HIGHHAPI FHIR: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP EndpointEPSS 0.7%CVE-2026-37459HIGHAn integer underflow in FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a craftEPSS 0.7%CVE-2022-46352HIGHA vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALAEPSS 0.7%CVE-2025-0704MEDIUMJoeyBling bootplus QrCodeController.java qrCode resource consumptionEPSS 0.7%CVE-2024-42943HIGHTenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the PPPOEPassword parameter in the fromAdvSetWan function. This EPSS 0.7%CVE-2024-34483HIGHOFPGroupDescStats in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via OFPBucket.len=0.EPSS 0.7%CVE-2024-24988MEDIUMExcessive resource consumption when sending long emoji names in user custom statusEPSS 0.7%CVE-2023-26044MEDIUMReactPHP's HTTP server continues parsing unused multipart parts after reaching limitsEPSS 0.7%CVE-2023-23616LOWDiscourse membership requests lack character limitEPSS 0.7%CVE-2022-4767HIGHDenial of Service in usememos/memosEPSS 0.7%CVE-2023-2831MEDIUMDenial of Service while unescaping a Markdown stringEPSS 0.7%CVE-2023-27484MEDIUMUnchecked fieldpath index in Composition's patches can lead to arbitrary memory allocation in crossplaneEPSS 0.7%CVE-2023-50020HIGHAn issue was discovered in open5gs v2.6.6. SIGPIPE can be used to crash AMF.EPSS 0.7%CVE-2023-23625MEDIUMDenial of service in HAMT Decoding in go-unixfs EPSS 0.7%CVE-2021-26945—An integer overflow leading to a heap-buffer overflow was found in OpenEXR in versions before 3.0.1. An attacker could use this flaw to crasEPSS 0.7%CVE-2019-5043MEDIUMAn exploitable denial-of-service vulnerability exists in the Weave daemon of the Nest Cam IQ Indoor, version 4620002. A set of TCP connectioEPSS 0.7%CVE-2026-59902HIGHNetty: Memory Exhaustion in SctpMessageCompletionHandlerEPSS 0.7%CVE-2024-4599HIGHDenial of service vulnerability in LAN MessengerEPSS 0.7%CVE-2023-38251MEDIUMAdobe Commerce | Uncontrolled Resource Consumption (CWE-400)EPSS 0.7%CVE-2026-58483HIGHmcp-searxng: Unbounded Response Body Read Bypasses URL Size Limit in `web_url_read`EPSS 0.7%