Falhas do tipo CWE-400

3.026 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2026-27852HIGHAn attacker that can send mail to a user can craft a message whose headers contain a very large number of email addresses or MIME parametersEPSS 0.5%CVE-2026-83333HIGHVulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3. EasiEPSS 0.5%CVE-2026-83330HIGHVulnerability in the Helidon product of Oracle Fusion Middleware (component: WebSocket). Supported versions that are affected are 4.0.0-4.5EPSS 0.5%CVE-2025-29898MEDIUMQsync CentralEPSS 0.5%CVE-2026-40988HIGHUnbounded DEFLATE Inflation in SAML 2.0 Service ProviderEPSS 0.5%CVE-2026-50878HIGHAn issue in the attachment handling component of Feuerhamster MailForm v1.1.0 allows attackers to cause a Denial of Service (DoS) via a crafEPSS 0.5%CVE-2026-88286HIGHGV-LPC2011/LPC2211 - PTZ Connection-State Accept-Loop Denial of ServiceEPSS 0.5%CVE-2021-4467HIGHPositive Technologies MaxPatrol 8 & XSpider Remote DoSEPSS 0.5%CVE-2024-25039HIGHIBM Engineering Requirements Management DOORS and DOORS Web Access is affected by multiple vulnerabilitiesEPSS 0.5%CVE-2026-34826MEDIUMRack: Unbounded Range Count in get_byte_ranges Enables DoSEPSS 0.5%CVE-2026-54609HIGHQTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwardingEPSS 0.5%CVE-2026-9137MEDIUMCSP Report Endpoint Log Flooding in MISP via Incorrect Size LimitEPSS 0.5%CVE-2026-42467HIGHAn issue was discovered in Open-SAE-J1939 thru commit b6caf884df46435e539b1ecbf92b6c29b345bdfe (2025-11-30) in SAE_J1939_Read_Binary_Data_TrEPSS 0.5%CVE-2024-37904MEDIUMDenial of service from maliciously configured Git repository in MinderEPSS 0.5%CVE-2026-46374HIGHSQLFluff: Uncontrolled Resource Consumption in ParserEPSS 0.5%CVE-2026-83276HIGHVulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webclient-http2). Supported versions that are affectedEPSS 0.5%CVE-2026-42342HIGHReact Router vulnerable to DoS via unbounded path expansion in __manifest endpointEPSS 0.5%CVE-2026-53539HIGHPython-Multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of serviceEPSS 0.5%CVE-2026-42544HIGHGranian: Unauthenticated DoS via WebSocket subprotocol header panicEPSS 0.5%CVE-2026-76679HIGHUnauthenticated Denial-of-Service Vulnerabilities in HPE Networking EdgeConnect SD-WAN GatewaysEPSS 0.5%