Weaknesses of type CWE-400

3,026 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2026-61155CRITICALVulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge). The supported version EPSS 0.5%CVE-2026-6022HIGHUncontrolled Resource Consumption Vulnerability in Telerik UI for ASP.NET AJAXEPSS 0.5%CVE-2024-35221MEDIUMDenial of service when publishing a package on rubygems.orgEPSS 0.5%CVE-2026-82260HIGHSvelteKit before 2.52.2 Memory Exhaustion via Remote Form DeserializationEPSS 0.5%CVE-2023-5333MEDIUM Denial of Service via multiple identical User IDs in /api/v4/users/idsEPSS 0.5%CVE-2024-21126MEDIUMVulnerability in the Oracle Database Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 19.EPSS 0.5%CVE-2026-82261HIGHSvelteKit before 2.52.2 CPU Exhaustion via Remote Form DeserializationEPSS 0.5%CVE-2026-54340HIGHh2o has HTTP/2 state amplificationEPSS 0.5%CVE-2023-53873HIGHSyncBreeze 15.2.24 Denial of Service via Login Endpoint OverflowEPSS 0.5%CVE-2026-36957HIGHDbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router V1.0.0 is vulnerable to Denial of Service via the boa web server URI handler. By initiatinEPSS 0.5%CVE-2026-50889HIGHAn input handling flaw in the HTTP refresh token process of LLDAP v0.6.2 allows attackers to cause a Denial of Service (DoS) via sending a cEPSS 0.5%CVE-2026-36958HIGHA denial-of-service vulnerability exists in the U-SPEED N300 V1.0.0 wireless router. By sending a large number of concurrent HTTP requests tEPSS 0.5%CVE-2026-89425HIGHjackson-core: UTF8DataInputJsonParser._reportInvalidToken() does not honor maxErrorTokenLength, allowing unbounded StringBuilder growthEPSS 0.5%CVE-2024-48989HIGHA vulnerability in the PROFINET stack implementation of the IndraDrive (all versions) of Bosch Rexroth allows an attacker to cause a denial EPSS 0.5%CVE-2024-39548HIGHJunos OS Evolved: Receipt of specific packets in the aftmand process will lead to a memory leakEPSS 0.5%CVE-2024-3508MEDIUMBzip2: compressed content bomb leads to denial of service of bombastic apiEPSS 0.5%CVE-2025-50101MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.EPSS 0.5%CVE-2025-43857MEDIUMnet-imap rubygem vulnerable to possible DoS by memory exhaustionEPSS 0.5%CVE-2024-39693HIGHNext.js Denial of Service (DoS) conditionEPSS 0.5%CVE-2026-17078MEDIUMIBM i is Affected By A Denial of Service Vulnerability in DRDA / DDM []EPSS 0.5%