Weaknesses of type CWE-400

3,034 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2025-31210MEDIUMThe issue was addressed with improved UI. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7. Processing web content may lead toEPSS 0.5%CVE-2025-2820MEDIUMDenial of ServiceEPSS 0.5%CVE-2023-28451HIGHAn issue was discovered in Technitium 11.0.2. There is a vulnerability (called BadDNS) in DNS resolving software, which triggers a resolver EPSS 0.5%CVE-2026-65112MEDIUMNVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause uncontrolled resource consumption. A succeEPSS 0.5%CVE-2026-68555MEDIUMcoturn: Chained mobility resumes allow authenticated remote memory exhaustionEPSS 0.5%CVE-2026-55497MEDIUMCloudreve: Server crash through image decompression/pixel bomb in thumbnail & avatar decoding (DoS)EPSS 0.5%CVE-2026-65115MEDIUMNVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker may cause uncontrolled resource consumption. A successEPSS 0.5%CVE-2024-36543CRITICALIncorrect access control in the Kafka Connect REST API in the STRIMZI Project 0.41.0 and earlier allows an attacker to deny the service for EPSS 0.5%CVE-2026-77357HIGHMesop: DoS in /hot-reload endpoint allows unauthenticated attacker to exhaust worker threads and crash the serverEPSS 0.5%CVE-2026-84364MEDIUMHono: Unbounded dot-notation nesting in `parseBody()` can cause memory exhaustionEPSS 0.5%CVE-2024-53458HIGHSysax Multi Server 6.99 is vulnerable to a denial of service (DoS) condition when processing specially crafted SSH packets.EPSS 0.5%CVE-2026-84375HIGHjs-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sourcesEPSS 0.5%CVE-2026-69244HIGHAIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)EPSS 0.5%CVE-2026-92362MEDIUMag-ui-protocol ag-ui SSE Frame sse.rs resource consumptionEPSS 0.5%CVE-2026-73566HIGHnode-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selectionEPSS 0.5%CVE-2020-1670MEDIUMJunos OS: EX4300 Series: High CPU load due to receipt of specific IPv4 packetsEPSS 0.5%CVE-2021-4115—There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion. The highEPSS 0.5%CVE-2026-83612HIGHxmldom: HTML raw-text closing-tag case mismatch causes output amplificationEPSS 0.5%CVE-2026-77354HIGHkin-openapi: Uncontrolled resource consumption in openapi3filter deepObject query parameter decodingEPSS 0.5%CVE-2026-73556MEDIUMvLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of CVE-2026-55574EPSS 0.5%