Fallos del tipo CWE-404
695 resultadosLiberação ou encerramento inadequado de recursos
Quando o software não libera corretamente recursos (conexões de banco, arquivo aberto, memória alocada, socket de rede) após o uso. O programa continua consumindo esses recursos até ficar sem espaço ou conexões disponíveis, causando falhas, lentidão ou negação de serviço.
Ejemplo
Um servidor web abre uma conexão com banco de dados para cada requisição, mas esquece de fechar a conexão quando termina. Após centenas de requisições, todas as conexões disponíveis estão esgotadas e novas requisições falham.
Cómo mitigar
Use padrões como try-with-resources (Java), context managers (Python), ou equivalentes na sua linguagem para garantir liberação automática. Implemente timeouts e monitore uso de recursos em produção para detectar vazamentos cedo.
CVE-2025-2957HIGHTRENDnet TEW-411BRP+ HTTP Request httpd sub_401DB0 null pointer dereferenceEPSS 0.4%CVE-2026-7701MEDIUMTelegram Desktop Bot API url_auth_box.cpp RequestButton null pointer dereferenceEPSS 0.4%CVE-2026-92365MEDIUMvllm-project vllm thinking_budget_state.py algorithmic complexityEPSS 0.4%CVE-2026-92356MEDIUMa2ui-project a2ui Update Components basic_functions.ts updateComponents resource consumptionEPSS 0.4%CVE-2025-29313HIGHUse of incorrectly resolved name or reference in OpenDaylight Service Function Chaining (SFC) Subproject SFC Sodium-SR4 and below allows attEPSS 0.4%CVE-2026-2957MEDIUMqinming99 dst-admin File BackupController.java deleteBackup denial of serviceEPSS 0.4%CVE-2024-12661MEDIUMIObit Advanced SystemCare Utimate IOCTL AscRegistryFilter.sys 0x8001E024 null pointer dereferenceEPSS 0.4%CVE-2026-8121MEDIUMOpen5GS NSSF conv.c ogs_sbi_parse_plmn_list denial of serviceEPSS 0.4%CVE-2025-55102HIGHA denial-of-service vulnerability exists in the NetX IPv6 component functionality of Eclipse ThreadX NetX Duo. A specially crafted network pEPSS 0.4%CVE-2023-1189LOWWiseCleaner Wise Folder Hider IoControlCode WiseFs64.sys 0x222410 denial of serviceEPSS 0.4%CVE-2026-84287MEDIUMNousResearch hermes-agent Session Chat api_server.py denial of serviceEPSS 0.4%CVE-2026-8731MEDIUMOpen5GS NRF client.c ogs_sbi_client_add denial of serviceEPSS 0.4%CVE-2026-8319MEDIUMaiwaves-cn agents cheshire_cat_core stray_cat.py recall_relevant_memories_to_working_memory resource consumptionEPSS 0.4%CVE-2026-8730MEDIUMOpen5GS NRF context.c ogs_sbi_nf_instance_set_id denial of serviceEPSS 0.4%CVE-2026-84886MEDIUMsimular-ai Agent-S OCR HTTP API ocr_server.py ImageData resource consumptionEPSS 0.4%CVE-2026-8270MEDIUMOpen5GS SMF ogs_nas_parse_qos_rules denial of serviceEPSS 0.4%CVE-2026-7536MEDIUMOpen5GS BSF pcfBindings bsf_sess_add_by_ip_address denial of serviceEPSS 0.4%CVE-2024-12657MEDIUMIObit Advanced SystemCare Utimate IOCTL AscRegistryFilter.sys 0x8001E000 null pointer dereferenceEPSS 0.4%CVE-2024-12653MEDIUMFabulaTech USB over Network IOCT ftusbbus2.sys 0x22040C null pointer dereferenceEPSS 0.4%CVE-2024-0886LOWPoikosoft EZ CD Audio Converter Activation denial of serviceEPSS 0.4%