Weaknesses of type CWE-400

3,034 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2025-30158HIGHNamelessMC Forum iframe width/height abuse causing UI-based Denial of ServiceEPSS 0.5%CVE-2026-83600MEDIUMNetdata: Streaming protocol chart slot guard off-by-one allows ~16 GiB allocation request, crashing parent agentEPSS 0.5%CVE-2026-9165HIGHStackrox: stackrox: unbounded graphql query depth allows authenticated denial of serviceEPSS 0.5%CVE-2026-73559MEDIUMvLLM: Completion prompt lists fan out into unbounded engine requestsEPSS 0.5%CVE-2026-30405HIGHAn issue in GoBGP gobgpd v.4.2.0 allows a remote attacker to cause a denial of service via the NEXT_HOP path attributeEPSS 0.5%CVE-2026-52814MEDIUMGogs: Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion)EPSS 0.5%CVE-2025-21549HIGHVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). The supported version that is affected EPSS 0.5%CVE-2026-85100MEDIUM2FastLabs agent-squad Streaming Agent Response Workflow orchestrator.ts AgentSquad.routeRequest resource consumptionEPSS 0.5%CVE-2024-3056HIGHPodman: kernel: containers in shared ipc namespace are vulnerable to denial of service attackEPSS 0.5%CVE-2026-92363MEDIUMag-ui-protocol ag-ui JSON sse_parser.cpp resource consumptionEPSS 0.5%CVE-2025-27669HIGHVasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Remote Network Scanning (XSPA)/DoS EPSS 0.5%CVE-2026-50018MEDIUMHoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve ActionsEPSS 0.5%CVE-2024-7567MEDIUMRockwell Automation Micro850/870 Vulnerable to denial-of-service Vulnerability via CIP/Modbus PortEPSS 0.5%CVE-2026-86452HIGHMISP Unauthenticated Mail Endpoints Allow Unbounded Storage Consumption and Request FloodingEPSS 0.5%CVE-2026-46627HIGHTwig: Sandbox resource exhaustion via unbounded `for` / `range()`EPSS 0.5%CVE-2026-44240HIGHbasic-ftp allows a malicious FTP server to cause client-side denial of service via unbounded multiline control response bufferingEPSS 0.5%CVE-2026-28872HIGHA resource exhaustion issue was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and EPSS 0.5%CVE-2023-23925HIGHSwitcher Client contains Regular Expression Denial of Service (ReDoS)EPSS 0.5%CVE-2024-34688HIGHDenial of service (DOS) in SAP NetWeaver AS Java (Meta Model Repository)EPSS 0.5%CVE-2025-55972HIGHA TCL Smart TV running a vulnerable UPnP/DLNA MediaRenderer implementation is affected by a remote, unauthenticated Denial of Service (DoS) EPSS 0.5%