Weaknesses of type CWE-400

3,026 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2026-8319MEDIUMaiwaves-cn agents cheshire_cat_core stray_cat.py recall_relevant_memories_to_working_memory resource consumptionEPSS 0.6%CVE-2026-84857MEDIUMsigoden aichat API Endpoint serve.rs memory allocationEPSS 0.6%CVE-2026-5986MEDIUMZod jsVideoUrlParser util.js getTime redosEPSS 0.6%CVE-2026-84886MEDIUMsimular-ai Agent-S OCR HTTP API ocr_server.py ImageData resource consumptionEPSS 0.6%CVE-2023-34397HIGHMercedes Benz head-unit NTG 6 contains functions to import or export profile settings over USB. During parsing you can trigger that the servEPSS 0.6%CVE-2026-70646HIGHaiosend: Deserialization of request body before signature verification (Pre-auth DoS) in webhook handlerEPSS 0.6%CVE-2023-50019MEDIUMAn issue was discovered in open5gs v2.6.6. InitialUEMessage, Registration request sent at a specific time can crash AMF due to incorrect errEPSS 0.6%CVE-2023-26597HIGHController DOS on sending error responseEPSS 0.6%CVE-2026-67437HIGHOliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)EPSS 0.6%CVE-2024-21651HIGHXWiki Denial of Service attack through attachmentsEPSS 0.6%CVE-2023-37263MEDIUMStrapi's field level permissions not being respected in relationship titleEPSS 0.6%CVE-2023-43767—Certain WithSecure products allow Denial of Service via the aepack archive unpack handler. This affects WithSecure Client Security 15, WithSEPSS 0.6%CVE-2026-63016MEDIUMApache InLong: Ordinary users can create new packagesEPSS 0.6%CVE-2022-41568HIGHLINE client for iOS before 12.17.0 might be crashed by sharing an invalid shared key of e2ee in group chat.EPSS 0.6%CVE-2026-40481HIGHmonetr: Unauthenticated Stripe webhook reads attacker-sized request bodies before signature validationEPSS 0.6%CVE-2023-21925MEDIUMVulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (component: Core). Supported versions thaEPSS 0.6%CVE-2023-48369MEDIUMLog Flooding due to specially crafted requests in different endpointsEPSS 0.6%CVE-2025-7074MEDIUMvercel hyper rimraf-standalone.js ignoreMap redosEPSS 0.6%CVE-2025-25186MEDIUMNet::IMAP vulnerable to possible DoS by memory exhaustionEPSS 0.6%CVE-2026-85443HIGHMOOS core-moos through 10.4.0 MOOSDB Accept Loop Denial of ServiceEPSS 0.6%