Weaknesses of type CWE-410

21 results

Pool de recursos insuficiente

A aplicação aloca um número fixo ou limitado de recursos (conexões de banco, threads, buffers) sem garantir que sempre haverá disponibilidade quando necessário. Quando o pool se esgota, novas requisições ficam bloqueadas, causando travamento, degradação severa de desempenho ou negação de serviço.

Example

Um servidor web configura um pool de 100 conexões de banco de dados. Se uma consulta lenta não libera a conexão a tempo, o pool enche e requisições subsequentes ficam penduradas indefinidamente, deixando o site fora do ar até reiniciar o serviço.

How to mitigate

Dimensione o pool conforme a carga esperada, implemente timeouts para liberar recursos presos, use monitoramento contínuo de uso de pool, e considere scaling dinâmico ou filas de espera com limite máximo para rejeitar graciosamente em vez de travar.

CVE-2022-40224MEDIUMA denial of service vulnerability exists in the web server functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A speciallyEPSS 64.7%CVE-2025-0453MEDIUMDenial of Service through Batched Queries in GraphQL in mlflow/mlflowEPSS 10.4%CVE-2022-2048HIGHIn Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up noEPSS 2.3%CVE-2025-27479HIGHKerberos Key Distribution Proxy Service Denial of Service VulnerabilityEPSS 2.0%CVE-2018-13815A vulnerability has been identified in SIMATIC S7-1200 (All versions), SIMATIC S7-1500 (All Versions < V2.6). An attacker could exhaust the EPSS 1.8%CVE-2019-13921A vulnerability has been identified in SIMATIC WinAC RTX (F) 2010 (All versions < SP3 Update 1). Affected versions of the software contain aEPSS 1.4%CVE-2021-1615HIGHCisco Embedded Wireless Controller Software for Catalyst Access Points Denial of Service VulnerabilityEPSS 1.3%CVE-2019-0056HIGHJunos OS: MX Series: An MPC10 Denial of Service (DoS) due to OSPF states transitioning to Down, causes traffic to stop forwarding through the device.EPSS 1.3%CVE-2026-58218MEDIUMSamba: dns signing dos via tkey name cache exhaustionEPSS 1.1%CVE-2023-7033MEDIUMInsufficient Resource Pool vulnerability in Ethernet function of Mitsubishi Electric Corporation MELSEC iQ-R series CPU module, MELSEC iQ-L EPSS 0.9%CVE-2022-20937MEDIUMA vulnerability in a feature that monitors RADIUS requests on Cisco Identity Services Engine (ISE) Software could allow an unauthenticated, EPSS 0.8%CVE-2023-38505HIGHDietPi-Dashboard Insufficient TLS Handshake PoolEPSS 0.8%CVE-2022-46679MEDIUM Dell PowerScale OneFS 8.2.x, 9.0.0.x - 9.4.0.x, contain an insufficient resource pool vulnerability. A remote unauthenticated attacker coulEPSS 0.8%CVE-2024-7392MEDIUMChargePoint Home Flex Bluetooth Low Energy Denial-of-Service VulnerabilityEPSS 0.5%CVE-2025-41653HIGHWeidmueller: Denial-of-Service Vulnerability in the web server functionality of Industrial Ethernet SwitchesEPSS 0.5%CVE-2025-27694MEDIUMDell Wyse Management Suite, versions prior to WMS 5.1, contains an Insufficient Resource Pool vulnerability. An unauthenticated attacker wiEPSS 0.4%CVE-2022-22191MEDIUMJunos OS: EX4300: PFE Denial of Service (DoS) upon receipt of a flood of specific ARP trafficEPSS 0.4%CVE-2026-34019MEDIUMBIG-IP BFD vulnerabilityEPSS 0.3%CVE-2025-2134LOWIBM Jazz Reporting Service Denial of ServiceEPSS 0.2%CVE-2025-12986MEDIUMDenial of Service Vulnerability in Silicon Labs WF200 and WGM160P DevicesEPSS 0.2%