Weaknesses of type CWE-400

3,030 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2026-21452HIGHMessagePack-Java Vulnerable to Remote Denial of Service via Malicious .msgpack Model File Triggering Unbounded EXT Payload AllocationEPSS 0.6%CVE-2023-20259HIGHA vulnerability in an API endpoint of multiple Cisco Unified Communications Products could allow an unauthenticated, remote attacker to causEPSS 0.6%CVE-2026-71310MEDIUMrclone: Unbounded HTTP CONNECT Response Headers Can Exhaust rclone MemoryEPSS 0.6%CVE-2024-4183MEDIUMMattermost versions 8.1.x before 8.1.12, 9.6.x before 9.6.1, 9.5.x before 9.5.3, 9.4.x before 9.4.5 fail to limit the number of active sessiEPSS 0.6%CVE-2025-20340HIGHCisco IOS XR Address Resolution Protocol Broadcast Storm VulnerabilityEPSS 0.6%CVE-2026-71643HIGHAn issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denEPSS 0.6%CVE-2026-68523HIGHFulgur: Unbounded page slicing from attacker-controlled CSS height causes denial of serviceEPSS 0.6%CVE-2026-53504HIGHThumbor has Regex Denial of Service (ReDoS) in `convolution` filterEPSS 0.6%CVE-2026-63495HIGHLibevent: Unbounded memory accumulation in WebSocket server via fragmented framesEPSS 0.6%CVE-2026-86000MEDIUMSoup Sieve: Polynomial-time ReDoS (O(n²)) in the `IDENTIFIER` / `VALUE` selector sub-patternsEPSS 0.6%CVE-2026-68537HIGHFulgur: Unbounded page slicing from attacker-controlled CSS height causes denial of serviceEPSS 0.6%CVE-2026-71647HIGHAn issue in EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denial of servicEPSS 0.6%CVE-2026-71641HIGHAn issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denEPSS 0.6%CVE-2026-73561HIGHHub: Unauthenticated WebSocket RPC Waiter Resource ExhaustionEPSS 0.6%CVE-2026-79378HIGHAn issue in the btm_acl_handle() function of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware v3.x and earlier allows attackers to cEPSS 0.6%CVE-2026-85999MEDIUMSoup Sieve: Polynomial-time ReDoS (O(n²)) in the whitespace/comment trimming regex `RE_WS_END` (triggers on VALID selectors)EPSS 0.6%CVE-2026-56018HIGHJavaScript::Minifier::XS versions before 0.16 for Perl leak memory on every call to minify(), allowing unbounded memory growthEPSS 0.6%CVE-2026-53505HIGHThumbor proportion filter allows unbounded post-transform resize leading to remote DoSEPSS 0.6%CVE-2026-84304HIGHgRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame FragmentationEPSS 0.6%CVE-2026-50196HIGHSteeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetchEPSS 0.6%