SiteShadow
Back to vulnerability library
Detected byCWE-aware static analysis

CWE-419 Uncontrolled Resource Consumption

Coverage: 3 rules in the SiteShadow rule registry target this CWE (registry v2.0.0). Regex 2Other-pattern 1 Also: Taint and heuristic analyzers may also detect related flows (see coverage for the authoritative list) Registry tagging shows intent, for sample-level behaviour and benchmarked gaps see known gaps.

What this means

SiteShadow flagged code paths where an attacker can cause the system to consume too much CPU, memory, disk, or network, often by sending large inputs, triggering expensive operations, or creating unbounded loops/queues.

Why it matters

Unbounded resource use can lead to outages or denial of service.

Safer examples

1) Put hard limits on inputs and work

Limit request body size, file upload size, query complexity, pagination, and recursion depth.

2) Add timeouts and circuit breakers

Set DB/query timeouts, HTTP timeouts, and background job time limits.

3) Rate limit expensive endpoints

Apply throttling and caching to expensive operations; prefer async processing for heavy tasks.

How SiteShadow detects it (high level)

References

---

← Back to Vulnerability Library

Catch this in your code with SiteShadow.

Every released SiteShadow scanner is free, including full project analysis, reports, patterns, dashboard access, and configured organization SSO.