Weaknesses of type CWE-400

3,030 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2026-42493HIGHx86 shadow paging is deprecatedEPSS 0.6%CVE-2026-68523HIGHFulgur: Unbounded page slicing from attacker-controlled CSS height causes denial of serviceEPSS 0.6%CVE-2026-50196HIGHSteeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetchEPSS 0.6%CVE-2023-3593MEDIUMServer crash via a specially crafted markdown inputEPSS 0.6%CVE-2026-94640HIGHRpcbind: unbounded memory allocation in rpcbind statistics tracking allows unauthenticated remote denial of serviceEPSS 0.6%CVE-2024-22332MEDIUMIBM Integration Bus for z/OS denial of serviceEPSS 0.6%CVE-2026-45713HIGHMailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizesEPSS 0.6%CVE-2025-5896MEDIUMtarojs taro index.js redosEPSS 0.6%CVE-2023-32341MEDIUMIBM Sterling B2B Integrator denial of serviceEPSS 0.6%CVE-2026-0889HIGHDenial-of-service in the DOM: Service Workers componentEPSS 0.6%CVE-2024-27800HIGHThis issue was addressed by removing the vulnerable code. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macEPSS 0.6%CVE-2026-18549HIGH@fastify/multipart vulnerable to Denial of Service via aborted upload after fileSize limitEPSS 0.6%CVE-2025-5892MEDIUMRocketChat parseMessage.js parseMessage redosEPSS 0.6%CVE-2024-11498MEDIUMResource exhaustion via Stack overflow in libjxlEPSS 0.6%CVE-2022-37907MEDIUMA vulnerability exists in the ArubaOS bootloader on 7xxx series controllers which can result in a denial of service (DoS) condition on an imEPSS 0.6%CVE-2025-5897MEDIUMvuejs vue-cli Markdown Code HtmlPwaPlugin.js HtmlPwaPlugin redosEPSS 0.6%CVE-2024-21523HIGHAll versions of the package images are vulnerable to Denial of Service (DoS) due to providing unexpected input types to several different fuEPSS 0.6%CVE-2023-42503—Apache Commons Compress: Denial of service via CPU consumption for malformed TAR fileEPSS 0.6%CVE-2024-27354HIGHAn issue was discovered in phpseclib 1.x before 1.0.23, 2.x before 2.0.47, and 3.x before 3.0.36. An attacker can construct a malformed certEPSS 0.6%CVE-2023-2785MEDIUMSpecially crafted search query can cause large log entries in postgresEPSS 0.6%