Weaknesses of type CWE-400

3,000 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2018-1064—libvirt version before 4.2.0-rc1 is vulnerable to a resource exhaustion as a result of an incomplete fix for CVE-2018-5748 that affects QEMUEPSS 2.9%CVE-2022-21680HIGHCubic catastrophic backtracking (ReDoS) in markedEPSS 2.8%CVE-2021-32640MEDIUMReDoS in Sec-Websocket-Protocol headerEPSS 2.8%CVE-2006-7229HIGHThe skge driver 1.5 in Linux kernel 2.6.15 on Ubuntu does not properly use the spin_lock and spin_unlock functions, which allows remote attaEPSS 2.8%CVE-2022-34701HIGHWindows Secure Socket Tunneling Protocol (SSTP) Denial of Service VulnerabilityEPSS 2.8%CVE-2021-22902—The actionpack ruby gem (a framework for handling and responding to web requests in Rails) before 6.0.3.7, 6.1.3.2 suffers from a possible dEPSS 2.8%CVE-2026-38361HIGHMultiple unauthenticated denial-of-service (DoS) issues in fohrloop dash-uploader v0.1.0 through v0.7.0a2. The chunked-upload handler (dash_EPSS 2.8%CVE-2023-36038HIGHASP.NET Core Denial of Service VulnerabilityEPSS 2.8%CVE-2024-7254HIGHStack overflow in Protocol Buffers Java LiteEPSS 2.8%CVE-2018-15443MEDIUMCisco Firepower Detection Engine TCP Intrusion Prevention System Rule Bypass VulnerabilityEPSS 2.8%CVE-2022-27781HIGHlibcurl provides the `CURLOPT_CERTINFO` option to allow applications torequest details to be returned about a server's certificate chain.DueEPSS 2.7%CVE-2022-21681HIGHExponential catastrophic backtracking (ReDoS) in markedEPSS 2.7%CVE-2018-14626MEDIUMPowerDNS Authoritative Server 4.1.0 up to 4.1.4 inclusive and PowerDNS Recursor 4.0.0 up to 4.1.4 inclusive are vulnerable to a packet cacheEPSS 2.7%CVE-2015-1916HIGHUnspecified vulnerability in IBM Java 8 before SR1 allows remote attackers to cause a denial of service via unknown vectors related to SSL/TEPSS 2.7%CVE-2021-20201—A flaw was found in spice in versions before 0.14.92. A DoS tool might make it easier for remote attackers to cause a denial of service (CPUEPSS 2.7%CVE-2024-38168HIGH.NET and Visual Studio Denial of Service VulnerabilityEPSS 2.7%CVE-2025-21230HIGHMicrosoft Message Queuing (MSMQ) Denial of Service VulnerabilityEPSS 2.7%CVE-2018-0285—A vulnerability in service logging for Cisco Prime Service Catalog could allow an authenticated, remote attacker to deny service to the userEPSS 2.7%CVE-2024-26215HIGHDHCP Server Service Denial of Service VulnerabilityEPSS 2.7%CVE-2021-43854HIGHInefficient Regular Expression Complexity in nltkEPSS 2.7%