Weaknesses of type CWE-400

3,026 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2025-65637HIGHA denial-of-service vulnerability exists in github.com/sirupsen/logrus when using Entry.Writer() to log a single-line payload larger than 64EPSS 0.6%CVE-2026-9496HIGHVersions of the package pacote from 11.2.7 and before 21.5.1 are vulnerable to Denial of Service (DoS) via the addGitSha function. An attackEPSS 0.6%CVE-2026-69222HIGHLiquidJS: Uncontrolled Resource Consumption in `join` filter allows template authors to bypass `memoryLimit` and crash the processEPSS 0.6%CVE-2026-82397HIGHTornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loopEPSS 0.6%CVE-2022-2741HIGHcan: denial-of-service can be triggered by a crafted CAN frameEPSS 0.6%CVE-2026-69209HIGHHttp4s: WebSocket decoder accepts unbounded message sizesEPSS 0.6%CVE-2026-38638HIGHAn issue in the with_argv function (/unistd/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafteEPSS 0.6%CVE-2026-63128HIGHRMCP: Unauthenticated permanent session-table leak in rmcp Streamable HTTP server transport leads to remote denial-of-serviceEPSS 0.6%CVE-2026-69203HIGHHttp4s Ember HTTP/2: does not enforce SETTINGS_MAX_CONCURRENT_STREAMSEPSS 0.6%CVE-2026-89407HIGHjackson-core: quadratic backtracking in NumberInput.PATTERN_FLOAT via looksLikeValidNumber() enables ReDoSEPSS 0.6%CVE-2022-23015—On BIG-IP versions 16.x before 16.1.0, 15.1.x before 15.1.4.1, and 14.1.2.6-14.1.4.4, when a Client SSL profile is configured on a virtual sEPSS 0.6%CVE-2024-10110HIGHDenial of Service in aimhubio/aimEPSS 0.6%CVE-2024-33498MEDIUMA vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating ManageEPSS 0.6%CVE-2025-60536HIGHAn issue in the Configure New Cluster interface of kafka-ui v0.6.0 to v0.7.2 allows attackers to cause a Denial of Service (DoS) via uploadiEPSS 0.6%CVE-2026-25819HIGHHMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 alEPSS 0.6%CVE-2026-4704HIGHDenial-of-service in the WebRTC: Signaling componentEPSS 0.6%CVE-2022-24118CRITICALCertain General Electric Renewable Energy products allow attackers to use a code to trigger a reboot into the factory default configuration.EPSS 0.6%CVE-2023-22664HIGHBIG-IP HTTP/2 profile vulnerabilityEPSS 0.6%CVE-2026-24001LOWjsdiff has a Denial of Service vulnerability in parsePatch and applyPatchEPSS 0.6%CVE-2026-42005MEDIUMInsufficient input validation of internal web serverEPSS 0.6%