Weaknesses of type CWE-400

3,033 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2024-55568HIGHAn issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380,EPSS 0.6%CVE-2026-33285HIGHLiquidJS: memoryLimit Bypass through Negative Range Values Leads to Process CrashEPSS 0.6%CVE-2025-26782HIGHAn issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330,EPSS 0.6%CVE-2026-86515MEDIUMvgmstream txtp txtp_parser.c add_entry resource consumptionEPSS 0.6%CVE-2025-21547CRITICALVulnerability in the Oracle Hospitality OPERA 5 product of Oracle Hospitality Applications (component: Opera Servlet). Supported versions tEPSS 0.6%CVE-2026-92879MEDIUMvgmstream mus_acm.c parse_mus resource consumptionEPSS 0.6%CVE-2024-24827MEDIUMNo rate limits on POST /uploads endpoint in DiscourseEPSS 0.6%CVE-2024-25355HIGHs3-url-parser 1.0.3 is vulnerable to Denial of service via the regexes component.EPSS 0.6%CVE-2023-45955—An issue discovered in Nanoleaf Light strip v3.5.10 allows attackers to cause a denial of service via crafted write binding attribute commanEPSS 0.6%CVE-2023-26437LOWDeterred spoofing attempts can lead to authoritative servers being marked unavailableEPSS 0.6%CVE-2024-34084HIGHMinder's Github Webhook Handler vulnerable to denial of service from un-validated requestsEPSS 0.6%CVE-2025-50077MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.42, 8.4.0EPSS 0.6%CVE-2025-50089MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 9.0.0-9.EPSS 0.6%CVE-2025-50079MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.EPSS 0.6%CVE-2026-33268MEDIUMNanoleaf Lines unauthenticated firmware file storeEPSS 0.6%CVE-2025-50091MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.EPSS 0.6%CVE-2025-55796HIGHThe openml/openml.org web application version v2.0.20241110 uses predictable MD5-based tokens for critical user workflows such as signup conEPSS 0.6%CVE-2025-0191MEDIUMDenial of Service in gaizhenbiao/chuanhuchatgptEPSS 0.6%CVE-2024-27686HIGHMikrotik RouterOS (x86) 6.40.5 through 6.49.10 (fixed in 7) allows a remote attacker to cause a denial of service (device crash) via craftedEPSS 0.6%CVE-2026-44630HIGHApache IoTDB: RPC service denial of service via unchecked Thrift string lengthEPSS 0.6%