Falhas do tipo CWE-400

3.026 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2020-11937MEDIUMResource exhaustion vulnerability in whoopsieEPSS 0.5%CVE-2026-28789HIGHOliveTin: Unauthenticated DoS via concurrent map writes in OAuth2 state handlingEPSS 0.5%CVE-2024-45420MEDIUMZoom Apps - Uncontrolled Resource ConsumptionEPSS 0.5%CVE-2025-52293HIGHA segmentation violaton in the gf_hevc_read_sps_bs_internal function (media_tools/av_parsers.c) of GPAC MP4Box v2.4 allows attackers to causEPSS 0.5%CVE-2024-3872LOWMattermost Mobile app versions 2.13.0 and earlier use a regular expression with polynomial complexity to parse certain deeplinks, which alloEPSS 0.5%CVE-2026-31935HIGHSuricata http2: unbounded resource consumptionEPSS 0.5%CVE-2024-25615MEDIUM An unauthenticated Denial-of-Service (DoS) vulnerability exists in the Spectrum service accessed via the PAPI protocol in ArubaOS 8.x. SuccEPSS 0.5%CVE-2026-48593MEDIUMUnbounded range expansion in cron describe causes memory exhaustion in oban_webEPSS 0.5%CVE-2026-76821HIGHOpenCTI: User-Controlled ReDoS in JSON Ingestion MapperEPSS 0.5%CVE-2020-8229—A memory leak in the OCUtil.dll library used by Nextcloud Desktop Client 2.6.4 can lead to a DoS against the host system.EPSS 0.5%CVE-2026-71486MEDIUMvLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output boundsEPSS 0.5%CVE-2026-0992LOWLibxml2: libxml2: denial of service via crafted xml catalogsEPSS 0.5%CVE-2021-4465HIGHReQuest Serious Play F3 Media Server <= 7.0.3 Remote DoSEPSS 0.5%CVE-2024-35185MEDIUMDenial of service of Minder Server with attacker-controlled REST endpointEPSS 0.5%CVE-2024-33382MEDIUMAn issue in Open5GS v.2.7.0 allows an attacker to cause a denial of service via the 64 unsuccessful UE/gnb registrationEPSS 0.5%CVE-2024-5423MEDIUMUncontrolled Resource Consumption in GitLabEPSS 0.5%CVE-2024-8041MEDIUMUncontrolled Resource Consumption in GitLabEPSS 0.5%CVE-2023-43786MEDIUMLibx11: stack exhaustion from infinite recursion in putsubimage()EPSS 0.5%CVE-2025-21548MEDIUMVulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python). Supported versions that are affected are 9.1.0EPSS 0.5%CVE-2024-43789HIGHDenial of service by the absence of restrictions on replies to posts in DiscourseEPSS 0.5%