Weaknesses of type CWE-400

3,033 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2024-5795HIGHDenial of Service vulnerability was identified in GitHub Enterprise Server that allowed resource exhaustionEPSS 0.6%CVE-2023-29333LOWMicrosoft Access Denial of Service VulnerabilityEPSS 0.6%CVE-2026-73228MEDIUMDjango REST framework: Potential bypass of Django `DATA_UPLOAD_MAX_MEMORY_SIZE` when parsing oversized JSON and urlencoded request bodies via DRF `request.data`EPSS 0.6%CVE-2023-24594MEDIUMBIG-IP TMM SSL vulnerabilityEPSS 0.6%CVE-2023-51847HIGHAn issue in obgm and Libcoap v.a3ed466 allows a remote attacker to cause a denial of service via thecoap_context_t function in the src/coap_EPSS 0.6%CVE-2024-44169HIGHThe issue was addressed with improved memory handling. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia EPSS 0.6%CVE-2026-9322HIGHIBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilitiesEPSS 0.6%CVE-2024-27100MEDIUMDenial of service via Staff Actions in DiscourseEPSS 0.6%CVE-2023-7326HIGHEpson Stylus SX510W Printer Remote Power Off DoSEPSS 0.6%CVE-2025-62854LOWFile Station 5EPSS 0.6%CVE-2023-39327MEDIUMOpenjpeg: malicious files can cause the program to enter a large loopEPSS 0.6%CVE-2021-47208MEDIUMThe Mojolicious module before 9.11 for Perl has a bug in format detection that can potentially be exploited for denial of service.EPSS 0.6%CVE-2026-22258HIGHSuricata DCERPC: unbounded fragment buffering leads to memory exhaustionEPSS 0.6%CVE-2024-42969HIGHTenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromSafeUrlFilter function. This vulnerabEPSS 0.6%CVE-2024-42950HIGHTenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the Go parameter in the fromSafeClientFilter function. This vulnEPSS 0.6%CVE-2024-20500MEDIUMA vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unEPSS 0.6%CVE-2024-42951HIGHTenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the mit_pptpusrpw parameter in the fromWizardHandle function. ThEPSS 0.6%CVE-2022-41932HIGHCreation of new database tables through login form on PostgreSQLEPSS 0.6%CVE-2026-26477MEDIUMAn issue in Dokuwiki v.2025-05-14b "Librarian" [56.2] allows a remote attacker to cause a denial of service via the media_upload_xhr() functEPSS 0.6%CVE-2024-27862MEDIUMA logic issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.6. Enabling Lockdown Mode while setting uEPSS 0.6%