Falhas do tipo CWE-400

3.026 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2026-33541MEDIUMTSPortal's Uncontrolled User Creation via Validation Side Effects Leads to Potential Denial of ServiceEPSS 0.4%CVE-2024-5055HIGHVulnerability of uncontrolled resource consumption in XAMPPEPSS 0.4%CVE-2026-68904HIGHnode-opcua: TCP Socket Leak (FIN-WAIT-2) via keepalive reconnection cycle - Resource ExhaustionEPSS 0.4%CVE-2026-41721MEDIUMSpring Data Commons Denial of Service via Data BindingEPSS 0.4%CVE-2026-33625HIGHLMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant_dtype in model config loadingEPSS 0.4%CVE-2025-40944HIGHA vulnerability has been identified in SIMATIC ET 200AL IM 157-1 PN (6ES7157-1AB00-0AB0) (All versions), SIMATIC ET 200MP IM 155-5 PN HF (6EEPSS 0.4%CVE-2026-55247CRITICALplone.app.event: Denial of service via iCalendar importEPSS 0.4%CVE-2026-55248CRITICALplone.app.portlets: Denial of service via RSS feed portletEPSS 0.4%CVE-2026-22690LOWpypdf has possible long runtimes for missing /Root object with large /Size valuesEPSS 0.4%CVE-2026-6416LOWTanium addressed an uncontrolled resource consumption vulnerability in Interact.EPSS 0.4%CVE-2024-7708HIGHFor requests that have a body, but reading the body may end up in reading 0 bytes, there is a buffer leak. This is particularly the case forEPSS 0.4%CVE-2026-23940HIGHDenial of Service via Oversized Package UploadEPSS 0.4%CVE-2024-44227HIGHThe issue was addressed with improved memory handling. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An app may be able to EPSS 0.4%CVE-2025-49595MEDIUMn8n Vulnerable to Denial of Service via Malformed Binary Data RequestsEPSS 0.4%CVE-2026-3116MEDIUMImproper Input Validation in Zoom Plugin Webhook HandlerEPSS 0.4%CVE-2026-22815MEDIUMAIOHTTP: Uncapped memory usage possible through aiohttp allowing unlimited trailer headersEPSS 0.4%CVE-2026-94408MEDIUMUncontrolled Resource Consumption in Elasticsearch Leading to denial of serviceEPSS 0.4%CVE-2026-22691LOWpypdf has possible long runtimes for malformed startxrefEPSS 0.4%CVE-2026-30662MEDIUMConcreteCMS v9.4.7 contains a Denial of Service (DoS) vulnerability in the File Manager component. The 'download' method in 'concrete/controEPSS 0.4%CVE-2019-25401HIGHBematech Printer MP-4200 TH Denial of ServiceEPSS 0.4%