Weaknesses of type CWE-400

3,030 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2023-23524HIGHA denial-of-service issue was addressed with improved input validation. This issue is fixed in tvOS 16.3.2, iOS 16.3.1 and iPadOS 16.3.1, waEPSS 0.6%CVE-2025-8537MEDIUMAxiomatic Bento4 mp4decrypt Mp4Decrypt.cpp SetDataSize allocation of resourcesEPSS 0.6%CVE-2024-47497HIGHJunos OS: SRX Series, QFX Series, MX Series and EX Series: Receiving specific HTTPS traffic causes resource exhaustionEPSS 0.6%CVE-2025-65891HIGHA GPU device-ID validation flaw in OneFlow v0.9.0 allows attackers to trigger a Denial of Dervice (DoS) by invoking flow.cuda.get_device_proEPSS 0.6%CVE-2024-37299MEDIUMDiscourse vulnerable to DoS via Tag GroupEPSS 0.6%CVE-2021-23047—On version 16.x before 16.1.0, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.3, and all versions of 13.1.x, 12.1.x and 11.6.x, when BIG-IP APEPSS 0.6%CVE-2025-48392HIGHApache IoTDB: DoS VulnerabilityEPSS 0.6%CVE-2024-21521HIGHAll versions of the package @discordjs/opus are vulnerable to Denial of Service (DoS) due to providing an input object with a property toStrEPSS 0.6%CVE-2026-55512MEDIUMnebula-mesh: Unauthenticated OIDC login endpoint allocates unbounded in-memory state entries without rate limitingEPSS 0.6%CVE-2025-9281HIGHArmorStart® LT - Multiple Denial-of-Service VulnerabilitiesEPSS 0.6%CVE-2025-9279HIGHArmorStart® LT - Multiple Denial-of-Service VulnerabilitiesEPSS 0.6%CVE-2025-9283HIGHArmorStart® LT - Multiple Denial-of-Service VulnerabilitiesEPSS 0.6%CVE-2025-9282HIGHArmorStart® LT - Multiple Denial-of-Service VulnerabilitiesEPSS 0.6%CVE-2025-43462HIGHThe issue was addressed with improved memory handling. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOEPSS 0.6%CVE-2024-23824MEDIUMmailcow ipixel flood attack leads to Denial of Service in admin pageEPSS 0.6%CVE-2026-21619LOWUnsafe Deserialization of Erlang Terms in hex_coreEPSS 0.6%CVE-2026-30041HIGHAn integer overflow in the PSD parser compnent of FastStone Image Viewer v8.3 allows attackers to execute arbitrary code or cause a Denial oEPSS 0.6%CVE-2026-74789HIGHScriban before 7.0.0 LoopLimit Bypass via Built-in OperationsEPSS 0.6%CVE-2022-46315HIGHThe ProfileSDK has defects introduced in the design process. Successful exploitation of this vulnerability may affect system availability. EPSS 0.6%CVE-2026-33285HIGHLiquidJS: memoryLimit Bypass through Negative Range Values Leads to Process CrashEPSS 0.6%