Weaknesses of type CWE-400

3,026 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2024-32269HIGHAn issue in Yonganda YAD-LOJ V3.0.561 allows a remote attacker to cause a denial of service via a crafted packet.EPSS 0.7%CVE-2025-46728HIGHcpp-httplib has Unbounded Memory Allocation in Chunked/No-Length RequestsEPSS 0.7%CVE-2026-27204MEDIUMWasmtime WASI implementations are vulnerable to guest-controlled resource exhaustionEPSS 0.7%CVE-2026-34829HIGHRack: Denial of Service via Unbounded Multipart File Upload Without Content-LengthEPSS 0.7%CVE-2020-15853MEDIUMsupybot-fedora implements the command 'refresh', that refreshes the cache of all users from FAS. This takes quite a while to run, and zodbotEPSS 0.7%CVE-2020-1903—An issue when unzipping docx, pptx, and xlsx documents in WhatsApp for iOS prior to v2.20.61 and WhatsApp Business for iOS prior to v2.20.61EPSS 0.7%CVE-2026-71314HIGHNuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island renderingEPSS 0.7%CVE-2026-34827HIGHRack: Algorithmic-Complexity DoS in Rack::Multipart::ParserEPSS 0.7%CVE-2024-21914MEDIUMRockwell Automation - FactoryTalk® View ME on PanelView™ Plus 7 Boot Terminal lack Security ProtectionsEPSS 0.7%CVE-2026-65819HIGHgopacket: Multiple layer decoders panic on crafted packets (out-of-bounds/underflow) enabling unauthenticated remote DoS via DecodingLayerParserEPSS 0.7%CVE-2023-42813MEDIUMDenial of service from malicious manifest in kyvernoEPSS 0.7%CVE-2024-3153MEDIUMUncontrolled Resource Consumption in mintplex-labs/anything-llmEPSS 0.7%CVE-2026-59200HIGHPillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()EPSS 0.7%CVE-2026-59161HIGHExcelize: Streaming GetRows row-bound bypass causes attacker-controlled allocationEPSS 0.7%CVE-2025-48795MEDIUMApache CXF: Denial of Service and sensitive data exposure in logsEPSS 0.7%CVE-2026-45357HIGHLiquidJS: Memory and render limit bypass via unbounded width padding in `date` filter (strftime)EPSS 0.7%CVE-2026-39320HIGHSignal K Server has an Unauthenticated Regular Expression Denial of Service (ReDoS) via WebSocket Subscription PathsEPSS 0.7%CVE-2026-25762HIGHAdonisJS vulnerable to Denial of Service (DoS) via Unrestricted Memory Buffering in PartHandler during File Type DetectionEPSS 0.7%CVE-2023-20176MEDIUMA vulnerability in the networking component of Cisco access point (AP) software could allow an unauthenticated, remote attacker to cause a tEPSS 0.7%CVE-2026-32588MEDIUMApache Cassandra: Authenticated DoS via ALTER ROLE Password HashingEPSS 0.7%