Weaknesses of type CWE-400

3,000 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2014-5418—GE Multilink Uncontrolled Resource ConsumptionEPSS 3.2%CVE-2019-1010266—lodash prior to 4.17.11 is affected by: CWE-400: Uncontrolled Resource Consumption. The impact is: Denial of service. The component is: DateEPSS 3.2%CVE-2021-4040—A flaw was found in AMQ Broker. This issue can cause a partial interruption to the availability of AMQ Broker via an Out of memory (OOM) conEPSS 3.1%CVE-2017-15132—A flaw was found in dovecot 2.0 up to 2.2.33 and 2.3.0. An abort of SASL authentication results in a memory leak in dovecot's auth client usEPSS 3.1%CVE-2022-1708—A vulnerability was found in CRI-O that causes memory or disk space exhaustion on the node for anyone with access to the Kube API. The ExecSEPSS 3.1%CVE-2022-21277MEDIUMVulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions thEPSS 3.1%CVE-2024-21392HIGH.NET and Visual Studio Denial of Service VulnerabilityEPSS 3.1%CVE-2018-16853HIGHSamba from version 4.7.0 has a vulnerability that allows a user in a Samba AD domain to crash the KDC when Samba is built in the non-defaultEPSS 3.1%CVE-2018-16492—A prototype pollution vulnerability was found in module extend <2.0.2, ~<3.0.2 that allows an attacker to inject arbitrary properties onto OEPSS 3.0%CVE-2023-24860HIGHMicrosoft Defender Denial of Service VulnerabilityEPSS 3.0%CVE-2022-31028HIGHPossible DDOS by establishing keep-alive connections with anonymous HTTP clients in MinIOEPSS 3.0%CVE-2024-26190HIGHMicrosoft QUIC Denial of Service VulnerabilityEPSS 3.0%CVE-2016-9589—Undertow in Red Hat wildfly before version 11.0.0.Beta1 is vulnerable to a resource exhaustion resulting in a denial of service. Undertow keEPSS 3.0%CVE-2019-11060HIGHHG100 contains an Uncontrolled Resource Consumption vulnerabilityEPSS 3.0%CVE-2024-30105HIGH.NET and Visual Studio Denial of Service VulnerabilityEPSS 2.9%CVE-2024-20672HIGH.NET Denial of Service VulnerabilityEPSS 2.9%CVE-2019-1703HIGHCisco Firepower Threat Defense Software Packet Processing Denial of Service VulnerabilityEPSS 2.9%CVE-2018-0048HIGHJunos OS: Memory exhaustion denial of service vulnerability in Routing Protocols Daemon (RPD) with Juniper Extension Toolkit (JET) support.EPSS 2.9%CVE-2017-16137—The debug module is vulnerable to regular expression denial of service when untrusted user input is passed into the o formatter. It takes arEPSS 2.9%CVE-2024-49096HIGHMicrosoft Message Queuing (MSMQ) Denial of Service VulnerabilityEPSS 2.9%