Weaknesses of type CWE-400

3,026 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2026-45756HIGHSymfony: JsonPath Evaluates Attacker-Controlled Regular Expressions in match()/search() Without Limits — ReDoSEPSS 0.6%CVE-2026-81875HIGHHAPI FHIR: SHCParser unbounded DEFLATE decompression causes denial of serviceEPSS 0.6%CVE-2026-45169HIGHIdira Privileged Access Manager (PAM) Self-Hosted Vault: Denial of Service due to Unexpected Input ProcessingEPSS 0.6%CVE-2026-47736HIGHPuma PROXY Protocol v1 Parser Allows Remote Memory ExhaustionEPSS 0.6%CVE-2026-55099HIGHicalendar: Algorithmic Complexity in EqualityEPSS 0.6%CVE-2026-81876HIGHHAPI FHIR: SHCParser DEFLATE infinite loop causes denial of serviceEPSS 0.6%CVE-2026-69222HIGHLiquidJS: Uncontrolled Resource Consumption in `join` filter allows template authors to bypass `memoryLimit` and crash the processEPSS 0.6%CVE-2026-85443HIGHMOOS core-moos through 10.4.0 MOOSDB Accept Loop Denial of ServiceEPSS 0.6%CVE-2026-9496HIGHVersions of the package pacote from 11.2.7 and before 21.5.1 are vulnerable to Denial of Service (DoS) via the addGitSha function. An attackEPSS 0.6%CVE-2026-45664MEDIUMImageMagick: Policy Bypass in MNG coder couldEPSS 0.6%CVE-2026-49851HIGHMistune: Potential DoS via quadratic-time parsing in parse_link_textEPSS 0.6%CVE-2026-69213HIGHHttp4s Ember HTTP/2: unbounded outbound frame queueEPSS 0.6%CVE-2026-38640HIGHA reachable unwrap in the __assert_fail function (/assert/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Service (DoSEPSS 0.6%CVE-2026-63452HIGHSuricata http1: repeated brotli compression bombs can cause excessive CPU consumptionEPSS 0.6%CVE-2026-55851HIGHNetty codec-haproxy: Signed-Byte Sentinel Collision in HAProxyMessageDecoder Leads to Unbounded Memory ExhaustionEPSS 0.6%CVE-2026-56745HIGHNetty SpdyHttpDecoder: ByteBuf Reference Leak on RST_STREAM Leads to Native Memory ExhaustionEPSS 0.6%CVE-2026-38637HIGHAn issue in the pthread_rwlockattr_setpshared() function of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a cEPSS 0.6%CVE-2026-38638HIGHAn issue in the with_argv function (/unistd/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafteEPSS 0.6%CVE-2026-69202HIGHHttp4s Ember HTTP/2: unbounded inbound body bufferingEPSS 0.6%CVE-2026-9563HIGHIn Eclipse Parsson published Maven Central artifacts before version 1.1.8, the JSON parser did not enforce a default maximum on the number oEPSS 0.6%