Weaknesses of type CWE-400

3,026 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2024-6838MEDIUMUncontrolled Resource Consumption in mlflow/mlflowEPSS 0.7%CVE-2026-4671HIGHjusthtml before 1.18.0 Denial of Service via CSS SelectorEPSS 0.7%CVE-2023-36161—An issue was discovered in Qubo Smart Plug 10A version HSP02_01_01_14_SYSTEM-10A, allows attackers to cause a denial of service (DoS) via WiEPSS 0.7%CVE-2024-55605HIGHSuricata allows stack overflow in transformsEPSS 0.7%CVE-2026-30998HIGHAn improper resource deallocation and closure vulnerability in the tools/zmqsend.c component of FFmpeg v8.0.1 allows attackers to cause a DeEPSS 0.7%CVE-2024-38616HIGHwifi: carl9170: re-fix fortified-memset warningEPSS 0.7%CVE-2023-45847MEDIUM Playbook Plugin Crash via Run ChecklistEPSS 0.6%CVE-2026-78551HIGHRansomLook Login Endpoint Allows Timing-Based Username Enumeration and Unthrottled Authentication AttemptsEPSS 0.6%CVE-2024-52979MEDIUMElasticsearch Uncontrolled Resource Consumption vulnerabilityEPSS 0.6%CVE-2025-61919HIGHRack is vulnerable to a memory-exhaustion DoS through unbounded URL-encoded body parsingEPSS 0.6%CVE-2026-40140HIGHHigh-Severity Pre-Authentication Vulnerability in BeyondTrust Remote Support and Privileged Remote AccessEPSS 0.6%CVE-2026-69152HIGHbrace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigationEPSS 0.6%CVE-2022-41770MEDIUMBIG-IP and BIG-IQ iControl REST vulnerability CVE-2022-41770EPSS 0.6%CVE-2026-56816HIGHNetty: Memory Exhaustion via HTTP/3 Reserved Frame TypesEPSS 0.6%CVE-2026-49293HIGHCPU exhaustion via O(n^2) BigInt construction on radix-prefixed integer literalsEPSS 0.6%CVE-2026-59941MEDIUMDompdf: Uncontrolled resource consumption based on declared BMP dimensionsEPSS 0.6%CVE-2022-20691MEDIUMA vulnerability in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Adaptive Telephone Adapter firmware could allow an unaEPSS 0.6%CVE-2026-49476HIGHSoup Sieve: Memory Exhaustion via Large Comma-Separated Selector Lists in soupsieveEPSS 0.6%CVE-2021-32821MEDIUMRegular expression Denial of Service in MooToolsEPSS 0.6%CVE-2026-49477HIGHSoup Sieve: Regular Expression Denial of Service (ReDoS) in soupsieve Selector ParserEPSS 0.6%