Falhas do tipo CWE-400

3.026 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2026-34293MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.0-8.0.45. EPSS 0.4%CVE-2026-60171MEDIUMVulnerability in the MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8EPSS 0.4%CVE-2024-6501LOWNetworkmanager: denial of serviceEPSS 0.4%CVE-2025-29484HIGHAn out-of-memory error in the parseABC_NS_SET_INFO function of libming v0.4.8 allows attackers to cause a Denial of Service (DoS) due to allEPSS 0.4%CVE-2026-34267MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.EPSS 0.4%CVE-2026-47008MEDIUMVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: InnoDB). Supported versions that are affected are MySQEPSS 0.4%CVE-2025-29487HIGHAn out-of-memory error in the parseABC_STRING_INFO function of libming v0.4.8 allows attackers to cause a Denial of Service (DoS) due to allEPSS 0.4%CVE-2026-91776HIGHjackson-databind: unbounded growth of the type id cache in TypeDeserializerBase retains every unknown raw type IDEPSS 0.4%CVE-2025-53481HIGHDenial of service vector on ipinfo/v0/norevisionEPSS 0.4%CVE-2026-60208CRITICALVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.4%CVE-2024-7610MEDIUMUncontrolled Resource Consumption in GitLabEPSS 0.4%CVE-2025-57614HIGHAn issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) Integer overflow and invalid input vulnerability in the cached method allEPSS 0.4%CVE-2026-17639MEDIUMCertain HP Smart Tank All in One – Potential Denial of ServiceEPSS 0.4%CVE-2025-27100MEDIUMAn authenticated user can crash lakeFS by exhausting server memoryEPSS 0.4%CVE-2022-47695—An issue was discovered Binutils objdump before 2.39.3 allows attackers to cause a denial of service or other unspecified impacts via functiEPSS 0.4%CVE-2024-2446MEDIUMMattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to limit the number of @-mentioEPSS 0.4%CVE-2026-5308MEDIUMMissing request body size limits on Zoom plugin HTTP endpointsEPSS 0.4%CVE-2025-59439HIGHAn issue was discovered in Samsung Mobile Processor, Wearable Processor and Modem Exynos 980, 990, 850, 1080, 9110, W920, W930, W1000 and MoEPSS 0.4%CVE-2023-49837MEDIUMWordPress embed-code plugin <= 2.3.6 - Denial of Service Attack vulnerabilityEPSS 0.4%CVE-2026-35034MEDIUMJellyfin: Potential Application DoS from excessively large SyncPlay group namesEPSS 0.4%