SiteShadow
Back to vulnerability library

CWE-400 Uncontrolled Resource Consumption

What this means

SiteShadow flagged code where untrusted input can cause excessive CPU, memory, disk, or network usage (unbounded loops, huge payloads, expensive regex, uncontrolled concurrency).

Why it matters

Resource exhaustion can cause denial of service.

Safer examples

1) Enforce request and payload limits

Add max request body sizes, max file sizes, and max list lengths (see INPUT01/02).

2) Add timeouts and backpressure

3) Add rate limits and quotas

Use per-IP/per-user throttling and quotas (see RATE01/02).

How SiteShadow detects it (high level)

References

---

← Back to Vulnerability Library

Request access View coverage