Weaknesses of type CWE-400

3,034 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2023-26157MEDIUMVersions of the package libredwg before 0.12.5.6384 are vulnerable to Denial of Service (DoS) due to an out-of-bounds read involving sectionEPSS 0.5%CVE-2026-21696HIGHEndless reprocessing/reupload of activity log data due to SQLite max parameters limit not being consideredEPSS 0.5%CVE-2022-24902LOWMemory issue in playing videosEPSS 0.5%CVE-2025-44650HIGHIn Netgear R7000 V1.3.1.64_10.1.36 and EAX80 V1.0.1.70_1.0.2, the USERLIMIT_GLOBAL option is set to 0 in the bftpd.conf configuration file. EPSS 0.5%CVE-2026-33204HIGHSimpleJWT has an Unauthenticated Denial of Service via JWE header tamperingEPSS 0.5%CVE-2023-34061HIGHCVE-2023-34061 – Gorouter route pruningEPSS 0.5%CVE-2023-3585MEDIUMchannel DoS by sharing a boards linkEPSS 0.5%CVE-2026-41135HIGHfree5GC PCF: Memory Leak via CORS Middleware Registration in HTTP Handler Leads to Denial of ServiceEPSS 0.5%CVE-2025-52322HIGHAn issue in Open5GS v2.7.2 and before allows a remote attacker to cause a denial of service via a crafted Create Session Request message to EPSS 0.5%CVE-2026-55588MEDIUMORAS CLI: Cyclic Referrer Graph Can Cause Unbounded Recursion and Resource ConsumptionEPSS 0.5%CVE-2025-50076MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.0-8.0.25. EPSS 0.5%CVE-2024-52980MEDIUMElasticsearch Uncontrolled Resource Consumption vulnerabilityEPSS 0.5%CVE-2024-22091LOWExcessive resource consumption due to lack to request path size limitsEPSS 0.5%CVE-2024-45736MEDIUMImproperly Formatted ‘INGEST_EVAL’ Parameter Crashes Splunk DaemonEPSS 0.5%CVE-2026-47476HIGHNVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource consumption. A successfuEPSS 0.5%CVE-2024-54658MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOSEPSS 0.5%CVE-2024-27088NONEes5-ext Regular Expression Denial of Service in `function#copy` and `function#toStringTokens`EPSS 0.5%CVE-2025-2586HIGHOls: unauthenticated metrics flooding in openshift lightspeed service leading to resource exhaustionEPSS 0.5%CVE-2025-67726HIGHTornado is Vulnerable to Quadratic DoS via Crafted Multipart ParametersEPSS 0.5%CVE-2026-28351MEDIUMManipulated RunLengthDecode streams can exhaust RAMEPSS 0.5%