Falhas do tipo CWE-400

3.026 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2018-16878MEDIUMA flaw was found in pacemaker up to and including version 2.0.1. An insufficient verification inflicted preference of uncontrolled processesEPSS 0.4%CVE-2026-10069HIGHShibby Tomato miniupnpd resource consumptionEPSS 0.4%CVE-2022-4986HIGHHirschmann EagleSDV Denial of Service via TLSEPSS 0.4%CVE-2024-57079HIGHA prototype pollution in the lib.deepMerge function of @zag-js/core v0.50.0 allows attackers to cause a Denial of Service (DoS) via supplyinEPSS 0.4%CVE-2024-44192MEDIUMThe issue was addressed with improved checks. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2,EPSS 0.4%CVE-2023-45028MEDIUMQTS, QuTS hero, QuTScloudEPSS 0.4%CVE-2026-7493MEDIUMAppointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.11.5 - Unauthenticated Denial of ServiceEPSS 0.4%CVE-2026-54338MEDIUMJupyterHub: Unauthenticated Denial of Service via Unbounded Username Logging on Failed LoginEPSS 0.4%CVE-2026-90928HIGHFile Browser through 2.63.23 Memory Exhaustion via subtitle endpointEPSS 0.4%CVE-2026-62326MEDIUMWeblate Has Uncontrolled Resource Consumption viaEPSS 0.4%CVE-2026-86255HIGHwger before 2.5 Uncontrolled Resource Consumption via date_sequenceEPSS 0.4%CVE-2026-90927HIGHfilebrowser through 2.63.23 Denial of Service via unbounded WebSocket messageEPSS 0.4%CVE-2026-86204HIGHPocketMine-MP before 5.39.2 Denial of Service via ModalFormResponsePacketEPSS 0.4%CVE-2026-91979HIGHVikunja before 2.6.0 Denial of Service via Decompression BombEPSS 0.4%CVE-2026-91969HIGHvikunja before 2.6.0 Resource Exhaustion via CSV MigrationEPSS 0.4%CVE-2026-61617HIGHPterodactyl Wings SFTP write path does not enforce disk quota, allowing node-wide disk exhaustionEPSS 0.4%CVE-2026-91971HIGHVikunja before 2.6.0 Denial of Service via Avatar UploadEPSS 0.4%CVE-2024-54546HIGHThe issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15. An app may be able to cause unexpected systeEPSS 0.4%CVE-2026-57914MEDIUMApache Kerby: StackOverflow on parsing deeply nested ASN1 structuresEPSS 0.4%CVE-2026-48987MEDIUMpyLoad: Unbounded Memory Growth Leading to DoS and Potential DDoS in EventManagerEPSS 0.4%