Weaknesses of type CWE-400

3,026 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2021-32821MEDIUMRegular expression Denial of Service in MooToolsEPSS 0.6%CVE-2026-27888MEDIUMpypdf: Manipulated FlateDecode XFA streams can exhaust RAMEPSS 0.6%CVE-2023-47150HIGHIBM Common Cryptographic Architecture denial of serviceEPSS 0.6%CVE-2026-14257HIGHbrace-expansion DoS via unbounded expansion length causing an out-of-memory process crashEPSS 0.6%CVE-2026-48050HIGHArc: Unauthenticated access to Go debug pprof endpoints leaks runtime state and enables CPU-burn DoSEPSS 0.6%CVE-2023-49809MEDIUMTodo plugin gets crashed and disabled by memberEPSS 0.6%CVE-2025-9466HIGHArmorStart® LT - Multiple Denial-of-Service VulnerabilitiesEPSS 0.6%CVE-2024-34953HIGHAn issue in taurusxin ncmdump v1.3.2 allows attackers to cause a Denial of Service (DoS) via memory exhaustion by supplying a crafted .ncm fEPSS 0.6%CVE-2025-3526HIGHSessionClicks in Liferay Portal 7.0.0 through 7.4.3.21, and Liferay DXP 7.4 GA through update 9, 7.3 GA through update 25, and older unsuppoEPSS 0.6%CVE-2023-27314HIGHDenial of Service Vulnerability in ONTAP 9EPSS 0.6%CVE-2025-5891MEDIUMUnitech pm2 Config.js redosEPSS 0.6%CVE-2025-3986MEDIUMApereo CAS CasConfigurationMetadataServerController.java redosEPSS 0.6%CVE-2023-46737LOWPossible endless data attack from attacker-controlled registry in cosignEPSS 0.6%CVE-2026-64868HIGHNew API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body loggingEPSS 0.6%CVE-2026-48619MEDIUMA flaw in Node.js HTTP/2 client allows a server to send an unlimited number of ORIGIN frames, which could lead to an Out of Memory error on EPSS 0.6%CVE-2021-47368HIGHenetc: Fix illegal access when reading affinity_hintEPSS 0.6%CVE-2025-61920HIGHAuthlib is vulnerable to Denial of Service via Oversized JOSE SegmentsEPSS 0.6%CVE-2026-15308HIGHIncremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarationsEPSS 0.6%CVE-2026-8319MEDIUMaiwaves-cn agents cheshire_cat_core stray_cat.py recall_relevant_memories_to_working_memory resource consumptionEPSS 0.6%CVE-2026-21728HIGHTempo query limit results in unbounded memory allocationEPSS 0.6%