Weaknesses of type CWE-400

3,033 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2026-52192HIGHAn issue in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_445C5C componenEPSS 0.6%CVE-2026-76646HIGHApache MyFaces: Denial of Service via Unbounded Request ParsingEPSS 0.6%CVE-2026-67862HIGHopen62541 1.5.5 contains a buffer-overflow in the high-level attribute reading logic in src/client/ua_client_highlevel.c. This allows a remoEPSS 0.6%CVE-2023-29139MEDIUMAn issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. When a user with checkuserlog permissions makes many CheckUEPSS 0.6%CVE-2026-26047MEDIUMMoodle: moodle: uncontrolled resource consumption in tex formula editor leading to denial of serviceEPSS 0.6%CVE-2026-68005HIGHAn issue in ACME mini_httpd 1.30 and prior allows a remote attacker to cause a denial of service via the HTTP request header parser in the hEPSS 0.6%CVE-2026-77037HIGHmulter vulnerable to Denial of Service via file descriptor leak on aborted uploadsEPSS 0.6%CVE-2026-52197HIGHAn issue in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_44af70 componenEPSS 0.6%CVE-2023-45196MEDIUMAdminer and AdminerEvo denial of service via HTTP redirectEPSS 0.6%CVE-2026-55446HIGHLangflow: Unauthenticated DoS through multipart form boundary file uploadEPSS 0.6%CVE-2026-68497HIGHjackson-databind: unbounded numeric parse in Duration and XMLGregorianCalendar deserialization allows CPU denial of serviceEPSS 0.6%CVE-2023-20882MEDIUMIn Cloud foundry routing release versions from 0.262.0 and prior to 0.266.0,a bug in the gorouter process can lead to a denial of service ofEPSS 0.6%CVE-2026-34043MEDIUMSerialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objectsEPSS 0.6%CVE-2024-34079LOWocto-sts allows unauthenticated attackers to cause unbounded CPU and memory usageEPSS 0.6%CVE-2026-81721HIGHopenssl_encrypt before 1.4.9 Denial of Service via KDFEPSS 0.6%CVE-2026-49842HIGHFreeSWITCH: Pre-authentication bandwidth amplification via `mod_verto` speed-test framesEPSS 0.6%CVE-2026-65785MEDIUMWindows DHCP Client Denial of Service VulnerabilityEPSS 0.6%CVE-2025-53042MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.EPSS 0.6%CVE-2025-53040MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.EPSS 0.6%CVE-2025-53044MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.43, 8.4.0EPSS 0.6%