Weaknesses of type CWE-400

3,026 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2026-67855HIGHopen62541 contains a heap use-after-free in the GDS PushManagement certificate update workflow when UA_ENABLE_GDS_PUSHMANAGEMENT is enabled.EPSS 0.5%CVE-2024-54730HIGHFlatnotes <v5.3.1 is vulnerable to denial of service through the upload image function.EPSS 0.5%CVE-2025-65890HIGHA device-ID validation flaw in OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) by calling flow.cuda.synchronize() with anEPSS 0.5%CVE-2026-67445MEDIUMMailpit: SMTP command parser buffers unbounded command lines before syntax rejectionEPSS 0.5%CVE-2024-28053LOWResource Exhaustion via the Invitation FeatureEPSS 0.5%CVE-2026-45822MEDIUMdecode-uri-component through 0.4.1 is vulnerable to denial of service. The decode() function splits input on '%' producing N tokens and callEPSS 0.5%CVE-2026-67446MEDIUMMailpit: Thumbnail generation decodes unbounded image dimensions before scalingEPSS 0.5%CVE-2026-47244MEDIUMNetty HTTP/2: Advertised MAX_CONCURRENT_STREAMS are not enforcedEPSS 0.5%CVE-2018-6554—Memory leak in the irda_bind function in net/irda/af_irda.c and later in drivers/staging/irda/net/af_irda.c in the Linux kernel before 4.17 EPSS 0.5%CVE-2023-33957LOWDenial of service from high number of artifact signatures in notationEPSS 0.5%CVE-2026-34445HIGHONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings.EPSS 0.5%CVE-2024-25451MEDIUMBento4 v1.6.0-640 was discovered to contain an out-of-memory bug via the AP4_DataBuffer::ReallocateBuffer() function.EPSS 0.5%CVE-2026-25579CRITICALNavidrome affected by Denial of Service and disk exhaustion via oversized `size` parameter in `/rest/getCoverArt` and `/share/img/<token>` endpointsEPSS 0.5%CVE-2020-1689MEDIUMJunos OS: EX4300-MP/EX4600/QFX5K Series: High CPU load due to receipt of specific layer 2 frames when deployed in a Virtual Chassis configurationEPSS 0.5%CVE-2024-23323MEDIUMExcessive CPU usage when URI template matcher is configured using regex in EnvoyEPSS 0.5%CVE-2026-45783HIGHlibp2p: Unvalidated PUT_VALUE records allow unbounded disk exhaustion on DHT server nodesEPSS 0.5%CVE-2024-4210MEDIUMUncontrolled Resource Consumption in GitLabEPSS 0.5%CVE-2025-6176HIGHBrotli decompression bomb DoS in scrapy/scrapyEPSS 0.5%CVE-2020-8557MEDIUMKubernetes node disk Denial of Service by writing to container /etc/hostsEPSS 0.5%CVE-2025-69873LOWajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is enaEPSS 0.5%