Weaknesses of type CWE-400

2,642 results

Consumo descontrolado de recursos (Esgotamento de recursos)

A aplicação não limita ou valida adequadamente a quantidade de recursos (memória, CPU, conexões, espaço em disco) que um usuário ou processo pode consumir. Um atacante explora isso enviando requisições malformadas ou em grande volume para esgotar os recursos disponíveis, causando indisponibilidade do serviço.

Example

Um servidor web aceita uploads sem limite de tamanho ou número simultâneo de conexões. Um atacante envia centenas de uploads gigantescos ou mantém conexões abertas indefinidamente, preenchendo a memória e o disco até o servidor travar e ficar inacessível para usuários legítimos.

How to mitigate

Implemente limites explícitos: tamanho máximo de requisição/upload, timeout de conexão, máximo de conexões simultâneas, rate limiting. Monitore consumo de recursos e configure alertas. Use pools de conexão e libere recursos automaticamente após uso.

CVE-2025-53722HIGHWindows Remote Desktop Services Denial of Service VulnerabilityEPSS 17.9%CVE-2024-31152MEDIUMThe LevelOne WBR-6012 router with firmware R0.40e6 is vulnerable to improper resource allocation within its web application, where a series EPSS 17.8%CVE-2019-14901HIGHA heap overflow flaw was found in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The vulnerabiliEPSS 16.9%CVE-2010-5107HIGHThe default configuration of OpenSSH through 6.1 enforces a fixed time limit between establishing a TCP connection and completing a login, wEPSS 16.5%CVE-2019-5737In Node.js including 6.x before 6.17.0, 8.x before 8.15.1, 10.x before 10.15.2, and 11.x before 11.10.1, an attacker can cause a Denial of SEPSS 16.2%CVE-2026-34650HIGHAdobe Commerce | Uncontrolled Resource Consumption (CWE-400)EPSS 15.9%CVE-2021-35559MEDIUMVulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported versions that are afEPSS 14.8%CVE-2023-38180HIGH.NET and Visual Studio Denial of Service VulnerabilityEPSS 14.8%KEVCVE-2022-24713HIGHRegular expression denial of service in Rust's regex crateEPSS 14.5%CVE-2026-34649HIGHAdobe Commerce | Uncontrolled Resource Consumption (CWE-400)EPSS 14.4%CVE-2024-8182HIGHFlowise Denial of ServiceEPSS 13.9%CVE-2021-21348MEDIUMXStream is vulnerable to an attack using Regular Expression for a Denial of Service (ReDos)EPSS 13.8%CVE-2023-22512HIGHThis High severity DoS (Denial of Service) vulnerability was introduced in version 5.6.0 of Confluence Data Center and Server. With a CVSS SEPSS 13.7%CVE-2022-3094HIGHAn UPDATE message flood may cause named to exhaust all available memoryEPSS 13.2%CVE-2022-20624HIGHCisco NX-OS Software Cisco Fabric Services Over IP Denial of Service VulnerabilityEPSS 12.4%CVE-2018-16844MEDIUMnginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive CPU usage. This issEPSS 12.4%CVE-2026-55450CRITICALLangflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leakEPSS 11.8%CVE-2024-6036HIGHDenial of Service in gaizhenbiao/chuanhuchatgptEPSS 10.9%CVE-2018-12121Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Denial of Service with large HTTP headers: By using a combinationEPSS 10.2%CVE-2019-10952Rockwell Automation CompactLogix 5370 Uncontrolled Resource ConsumptionEPSS 10.0%