Falhas do tipo CWE-400

3.026 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2026-34404MEDIUMNuxt OG Image vulnerable to DoS via image generationEPSS 0.5%CVE-2026-50879HIGHAn issue in the uploadPostHandler component of Andrei Marcu linx-server v2.3.8 allows attackers to cause a Denial of Service (DoS) via a craEPSS 0.5%CVE-2024-37904MEDIUMDenial of service from maliciously configured Git repository in MinderEPSS 0.5%CVE-2026-88286HIGHGV-LPC2011/LPC2211 - PTZ Connection-State Accept-Loop Denial of ServiceEPSS 0.5%CVE-2025-55197MEDIUMpypdf's Manipulated FlateDecode streams can exhaust RAMEPSS 0.5%CVE-2022-48716HIGHASoC: codecs: wcd938x: fix incorrect used of portidEPSS 0.5%CVE-2025-44531HIGHAn issue in Realtek RTL8762EKF-EVB RTL8762E SDK v1.4.0 allows attackers to cause a Denial of Service (DoS) via sending a crafted before a paEPSS 0.5%CVE-2025-70886HIGHAn issue in halo v.2.22.4 and before allows a remote attacker to cause a denial of service via a crafted payload to the public comment submiEPSS 0.5%CVE-2025-62706MEDIUMAuthlib : JWE zip=DEF decompression bomb enables DoSEPSS 0.5%CVE-2024-47239MEDIUMDell PowerScale OneFS versions 8.2.2.x through 9.9.0.0 contain an uncontrolled resource consumption vulnerability. A remote low privileged aEPSS 0.5%CVE-2026-24485HIGHImageMagick: Infinite loop vulnerability when parsing a PCD fileEPSS 0.5%CVE-2024-22164MEDIUMDenial of Service of an Investigation in Splunk Enterprise Security through Investigation attachmentsEPSS 0.5%CVE-2022-32505HIGHAn issue was discovered on certain Nuki Home Solutions devices. It is possible to send multiple BLE malformed packets to block some of the fEPSS 0.5%CVE-2019-15264HIGHCisco Aironet Access Points and Catalyst 9100 Access Points CAPWAP Denial of Service VulnerabilityEPSS 0.5%CVE-2024-39810MEDIUMServer crash via Elasticsearch certificate fileEPSS 0.5%CVE-2026-35406MEDIUMAardvark-dns has incorrect error handling for malformed tcp packetsEPSS 0.5%CVE-2024-33618HIGHUncontrolled Resource Consumption in Bosch VMS Central Server in Bosch VMS 12.0.1 allows attackers to consume excessive amounts of disk spEPSS 0.5%CVE-2026-76700MEDIUMUnauthenticated Denial-of-Service Vulnerabilities in HPE Networking EdgeConnect SD-WAN GatewaysEPSS 0.5%CVE-2024-53851MEDIUMPartial denial of service via inline oneboxes in DiscourseEPSS 0.5%CVE-2026-6797MEDIUMSanluan PublicCMS DocToHtmlUtils.java ZipSecureFile.setMinflateRatio resource consumptionEPSS 0.5%