Weaknesses of type CWE-400

3,026 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2024-38520MEDIUMSoftEther VPN with L2TP - 2.75x AmplificationEPSS 0.5%CVE-2025-30476MEDIUMDell PowerScale InsightIQ, version 5.2, contains an uncontrolled resource consumption vulnerability. An unauthenticated attacker with remoteEPSS 0.5%CVE-2025-21545HIGHVulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch). Supported versions that are afEPSS 0.5%CVE-2025-6921MEDIUMRegular Expression Denial of Service (ReDoS) in huggingface/transformersEPSS 0.5%CVE-2025-67133HIGHAn issue in Hero Motocorp Vida V1 Pro 2.0.7 allows a local attacker to cause a denial of service via the BLE componentEPSS 0.5%CVE-2021-44319HIGHParrot AR.Drone 1 and AR.Drone 2 are vulnerable to Denial of Service. The Parrot AR.Drone platform is vulnerable to Wi-Fi deauthentication aEPSS 0.5%CVE-2026-55520HIGHProtego: Exponential backtracking ReDoS in robots.txt URL wildcard matchingEPSS 0.5%CVE-2026-28874HIGHThe issue was addressed with improved checks. This issue is fixed in iOS 26.4 and iPadOS 26.4. A remote attacker may cause an unexpected appEPSS 0.5%CVE-2026-85107MEDIUMNousResearch hermes-agent Electron Main Process main.ts resourceBufferFromUrl allocation of resourcesEPSS 0.5%CVE-2026-84833MEDIUMntegrals openbrowser Browser Agent Message Construction agent.ts resource consumptionEPSS 0.5%CVE-2025-53023MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are 8.0.0-EPSS 0.5%CVE-2020-1668MEDIUMJunos OS: EX2300 Series: High CPU load due to receipt of specific multicast packets on layer 2 interfaceEPSS 0.5%CVE-2025-50094MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.42, 8.4.5 EPSS 0.5%CVE-2026-79658HIGHEch0 before 5.0.1 Denial of Service via Accept-LanguageEPSS 0.5%CVE-2026-33232HIGHAutoGPT: Unauthenticated DoS via Disk Space ExhaustionEPSS 0.5%CVE-2026-87908HIGHmultiparty vulnerable to Denial of Service via unbounded part-header accumulationEPSS 0.5%CVE-2026-85585HIGHSiYuan before v3.8.2 Unbounded Memory Consumption via ControlConcurrencyEPSS 0.5%CVE-2023-45810MEDIUMOpenFGA denial of serviceEPSS 0.5%CVE-2026-67855HIGHopen62541 contains a heap use-after-free in the GDS PushManagement certificate update workflow when UA_ENABLE_GDS_PUSHMANAGEMENT is enabled.EPSS 0.5%CVE-2026-41680HIGHMarked: OOM Denial of Service via Infinite Recursion in marked TokenizerEPSS 0.5%