Weaknesses of type CWE-400

3,026 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2025-9278HIGHArmorStart® LT - Multiple Denial-of-Service VulnerabilitiesEPSS 0.5%CVE-2025-9280HIGHArmorStart® LT - Multiple Denial-of-Service VulnerabilitiesEPSS 0.5%CVE-2026-45680MEDIUMOpenTelemetry eBPF Instrumentation: Unbounded BPF internal metrics replay can exhaust CPUEPSS 0.5%CVE-2026-34230MEDIUMRack: Quadratic complexity in Rack::Utils.select_best_encoding via wildcard Accept-Encoding headerEPSS 0.5%CVE-2026-46689HIGHKanidm: Unauthenticated process abort via SCIM filter stack exhaustionEPSS 0.5%CVE-2026-42391HIGHAn unauthenticated attacker can send an IMAP ID command with a very large number of parameters before logging in, which causes memory and CPEPSS 0.5%CVE-2024-41727HIGHBIG-IP TMM vulnerabilityEPSS 0.5%CVE-2026-53580HIGHTrilium arbitrary file read and denial of service via file:// URLs in the automatic image-download featureEPSS 0.5%CVE-2026-18464HIGHWP Maps Pro < 6.1.3 - Unauthenticated Denial of ServiceEPSS 0.5%CVE-2025-9670MEDIUMmixmark-io turndown commonmark-rules.js redosEPSS 0.5%CVE-2025-52288HIGHAssertion failure in function ngap_build_downlink_nas_transport in file src/amf/ngap-build.c, the Access and Mobility Management Function (AEPSS 0.5%CVE-2024-43806MEDIUM`rustix::fs::Dir` iterator with the `linux_raw` backend can cause memory explosionEPSS 0.5%CVE-2023-41294—The DP module has a service hijacking vulnerability.Successful exploitation of this vulnerability may affect some Super Device services.EPSS 0.5%CVE-2023-29046MEDIUMConnections to external data sources, like e-mail autoconfiguration, were not terminated in case they hit a timeout, instead those connectioEPSS 0.5%CVE-2024-42426MEDIUMDell PowerScale OneFS Versions 9.5.0.x through 9.8.0.x contain an uncontrolled resource consumption vulnerability. A low privilege remote atEPSS 0.5%CVE-2026-74785HIGHScriban before 7.0.0 Denial of Service via Unbounded Resource ConsumptionEPSS 0.5%CVE-2024-39551HIGHJunos OS: SRX Series and MX Series with SPC3 and MS-MPC/MIC: Receipt of specific packets in H.323 ALG causes traffic dropEPSS 0.5%CVE-2025-53053MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.0-8.0.43, EPSS 0.5%CVE-2025-53054MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.43, 8.4.0EPSS 0.5%CVE-2024-30915MEDIUMAn issue was discovered in OpenDDS commit b1c534032bb62ad4ae32609778de6b8d6c823a66, allows a local attacker to cause a denial of service andEPSS 0.5%