Weaknesses of type CWE-400

3,026 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2026-31247HIGHDocling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks thru 2.61.0. The backend uses etree.parse() to parse XML fileEPSS 0.5%CVE-2026-48208MEDIUMDenial-of-Service via SVG Rendering in TicketEPSS 0.5%CVE-2025-24235MEDIUMA memory initialization issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, mEPSS 0.5%CVE-2026-41324HIGHbasic-ftp vulnerable to denial of service via unbounded memory consumption in Client.list()EPSS 0.5%CVE-2026-89147HIGHNet-SNMP through 5.9.5.2 Denial of Service via Blocking Unauthenticated SMUX ReadEPSS 0.5%CVE-2026-42583HIGHNetty: Lz4FrameDecoder resource exhaustionEPSS 0.5%CVE-2026-33375MEDIUMGrafana MSSQL Data Source Plugin: Restriction Bypass Leading to OOM DoSEPSS 0.5%CVE-2024-53693HIGHQTS, QuTS heroEPSS 0.5%CVE-2025-50095MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 9.0.0-9.EPSS 0.5%CVE-2023-33958MEDIUMDefault `maxSignatureAttempts` in `notation verify` enables an endless data attack in notationEPSS 0.5%CVE-2025-55521MEDIUMAn issue in the component /settings/localisation of Akaunting v3.1.18 allows authenticated attackers to cause a Denial of Service (DoS) via EPSS 0.5%CVE-2025-9465HIGHArmorStart® LT - Multiple Denial-of-Service VulnerabilitiesEPSS 0.5%CVE-2024-56921HIGHAn issue was discovered in Open5gs v2.7.2. InitialUEMessage, Registration request sent at a specific time can crash AMF due to incorrect errEPSS 0.5%CVE-2025-26481HIGHDell PowerScale OneFS, versions 9.4.0.0 through 9.9.0.0, contains an uncontrolled resource consumption vulnerability. A remote unprivileged EPSS 0.5%CVE-2025-52961HIGHJunos OS Evolved: PTX Series except PTX10003: An unauthenticated adjacent attacker sending specific valid traffic can cause a memory leak in cfmman leading to FPC crash and restartEPSS 0.5%CVE-2024-44160HIGHA buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7, macOS VentuEPSS 0.5%CVE-2025-25374HIGHIn NASA cFS (Core Flight System) Aquila, it is possible to put the onboard software in a state that will prevent the launch of any external EPSS 0.5%CVE-2026-33605HIGHAn unauthenticated attacker can crash the ManageSieve login process by sending a small malformed command before authenticating. If running iEPSS 0.5%CVE-2026-46689HIGHKanidm: Unauthenticated process abort via SCIM filter stack exhaustionEPSS 0.5%CVE-2026-42391HIGHAn unauthenticated attacker can send an IMAP ID command with a very large number of parameters before logging in, which causes memory and CPEPSS 0.5%