Weaknesses of type CWE-400

3,026 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2024-53458HIGHSysax Multi Server 6.99 is vulnerable to a denial of service (DoS) condition when processing specially crafted SSH packets.EPSS 0.5%CVE-2025-20162HIGHA vulnerability in the DHCP snooping security feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a fuEPSS 0.5%CVE-2026-6780HIGHDenial-of-service in the Audio/Video: Playback componentEPSS 0.5%CVE-2026-4726HIGHDenial-of-service in the XML componentEPSS 0.5%CVE-2025-43772HIGHKaleo Forms Admin in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.4 GA, 7.3 GA through update 27, and older unsupported versions EPSS 0.5%CVE-2026-10143HIGHkafka-python prior to 2.3.2 DoS via SCRAM Iteration Count in scram.pyEPSS 0.5%CVE-2025-3602HIGHLiferay Portal 7.4.0 through 7.4.3.97, and Liferay DXP 2023.Q3.1 through 2023.Q3.2, 7.4 GA through update 92, 7.3 GA through update 35, and EPSS 0.5%CVE-2026-4727HIGHDenial-of-service in the Libraries component in NSSEPSS 0.5%CVE-2026-6781HIGHDenial-of-service in the Audio/Video: Playback componentEPSS 0.5%CVE-2023-35191MEDIUMUncontrolled resource consumption for some Intel(R) SPS firmware versions may allow a privileged user to potentially enable denial of servicEPSS 0.5%CVE-2026-34593HIGHAsh Framework: Ash.Type.Module.cast_input/2 atom exhaustion via unchecked Module.concat allows BEAM VM crashEPSS 0.5%CVE-2026-33155HIGHDeepDiff has Memory Exhaustion DoS through SAFE_TO_IMPORTEPSS 0.5%CVE-2025-55634HIGHIncorrect access control in the RTMP server settings of Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_250EPSS 0.5%CVE-2026-82235HIGHfilebrowser through 2.63.23 Denial of Service via named pipesEPSS 0.5%CVE-2023-36841HIGHJunos OS: MX Series: Receipt of malformed TCP traffic will cause a Denial of ServiceEPSS 0.5%CVE-2023-48297HIGHDiscourse vulnerable to unlimited mentioned users in message serializerEPSS 0.5%CVE-2023-45956HIGHAn issue discovered in Govee LED Strip v3.00.42 allows attackers to cause a denial of service via crafted Move and MoveWithOnoff commands.EPSS 0.5%CVE-2026-33287HIGHLiquidJS has Exponential Memory Amplification through its replace_first Filter $& PatternEPSS 0.5%CVE-2024-34045HIGHThe O-RAN E2T I-Release Prometheus metric Increment function can crash in sctpThread.cpp for message.peerInfo->counters[IN_INITI][MSG_COUNTEEPSS 0.5%CVE-2025-58157HIGHgnark affected by denial of service when computing scalar multiplication using fake-GLV algorithmEPSS 0.5%