Weaknesses of type CWE-400

3,033 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2026-73413HIGHShescape: Quadratic-time denial of service in flag-protectionEPSS 0.6%CVE-2026-40303HIGHzrok allows unauthenticated DoS via unbounded memory allocation in striped session cookie parsingEPSS 0.6%CVE-2026-33169MEDIUMRails Active Support has a possible ReDoS vulnerability in number_to_delimitedEPSS 0.6%CVE-2026-44630HIGHApache IoTDB: RPC service denial of service via unchecked Thrift string lengthEPSS 0.6%CVE-2023-39219HIGHAdmin Console Denial of Service via Java class enumerationEPSS 0.6%CVE-2022-47556MEDIUMUncontrolled Resource Consumption in Ormazabal productsEPSS 0.6%CVE-2026-36590HIGHAn issue in EMQ NanoMQ v.0.24.9 allows a remote attacker to cause a denial of service via the nni_qos_db_set function in broker_tcp.c componEPSS 0.6%CVE-2022-27600MEDIUMQTS, QuTS hero, QuTScloudEPSS 0.6%CVE-2023-39329MEDIUMOpenjpeg: resource exhaustion will occur in the opj_t1_decode_cblks function in the tcd.cEPSS 0.6%CVE-2026-68924MEDIUMMobSF: Zip Bomb Denial of Service via Per-File Size Limit Bypass in ZIP/APK ExtractionEPSS 0.6%CVE-2025-50080MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Stored Procedure). Supported versions that are affected are 8EPSS 0.6%CVE-2024-56940HIGHAn issue in the profile image upload function of LearnDash v6.7.1 allows attackers to cause a Denial of Service (DoS) via excessive file uplEPSS 0.6%CVE-2024-5216HIGHDenial of Service in mintplex-labs/anything-llmEPSS 0.6%CVE-2025-29957MEDIUMWindows Deployment Services Denial of Service VulnerabilityEPSS 0.6%CVE-2025-41677MEDIUMResource Exhaustion via POST Requests to send-mail ActionEPSS 0.6%CVE-2026-22259HIGHSuricata dnp3: unbounded transaction growthEPSS 0.6%CVE-2026-54268HIGHAngular: Denial of Service (DoS) via OOM in Date Formatting (formatDate)EPSS 0.6%CVE-2022-1677—In OpenShift Container Platform, a user with permissions to create or modify Routes can craft a payload that inserts a malformed entry into EPSS 0.6%CVE-2023-29139MEDIUMAn issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. When a user with checkuserlog permissions makes many CheckUEPSS 0.6%CVE-2026-19500HIGHSureForms contains an uncontrolled resource consumption vulnerabilityEPSS 0.6%