Weaknesses of type CWE-400

3,027 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2026-45765HIGHSuricata dnp3: unbounded reassembly can lead to resource exhaustionEPSS 0.6%CVE-2023-23689MEDIUM Dell PowerScale nodes A200, A2000, H400, H500, H600, H5600, F800, F810 integrated hardware management software contains an uncontrolled resEPSS 0.6%CVE-2023-22400HIGHJunos OS Evolved: A specific SNMP GET operation and a specific CLI commands cause resources to leak and eventually the evo-pfemand process will crashEPSS 0.6%CVE-2026-45766HIGHSuricata nfs: unbounded stateful structures can lead to resource exhaustionEPSS 0.6%CVE-2026-59886HIGHpyasn1: Uncontrolled resource consumption when converting decoded REAL valuesEPSS 0.6%CVE-2023-1580HIGHUncontrolled resource consumption in the logging feature in Devolutions Gateway 2023.1.1 and earlier allows an attacker to cause a denial ofEPSS 0.6%CVE-2026-67318MEDIUMaxios 1.13.0 before 1.18.0 maxBodyLength Bypass via HTTP/2EPSS 0.6%CVE-2025-32472MEDIUMDoS attack by conducting a slowloris-type attackEPSS 0.6%CVE-2026-50193MEDIUMjackson-databind: Deeply nested JsonNode throws StackOverflowError for toString()EPSS 0.6%CVE-2023-35053HIGHIn JetBrains YouTrack before 2023.1.10518 a DoS attack was possible via Helpdesk formsEPSS 0.6%CVE-2025-5895MEDIUMMetabase dom.js parseDataUri redosEPSS 0.6%CVE-2026-53965MEDIUMMCP PHP SDK: Unbounded SSE buffer in HttpTransport enables client-side denial of serviceEPSS 0.6%CVE-2024-30170HIGHPrivX before 34.0 allows data exfiltration and denial of service via the REST API. This is fixed in minor versions 33.1, 32.3, 31.3, and latEPSS 0.6%CVE-2026-32936HIGHCoreDNS DoH GET path missing size validation causes CPU and memory amplificationEPSS 0.6%CVE-2026-33750MEDIUMbrace-expansion: Zero-step sequence causes process hang and memory exhaustionEPSS 0.6%CVE-2023-28763MEDIUMDenial of Service in SAP NetWeaver AS for ABAP and ABAP PlatformEPSS 0.6%CVE-2023-27270MEDIUMDenial of Service (DoS) in SAP NetWeaver AS for ABAP and ABAP PlatformEPSS 0.6%CVE-2024-8454MEDIUMPLANET Technology switch devices - Swctrl service DoS attackEPSS 0.6%CVE-2026-100650HIGHvLLM before 0.29.0 Resource Exhaustion via Unbounded Media MaterializationEPSS 0.6%CVE-2023-25618MEDIUMDenial of Service (DoS) vulnerability in SAP NetWeaver AS for ABAP and ABAP PlatformEPSS 0.6%