Falhas do tipo CWE-400

3.026 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2020-3508HIGHCisco IOS XE Software for Cisco ASR 1000 Series 20-Gbps Embedded Services Processor IP ARP Denial of Service VulnerabilityEPSS 0.4%CVE-2026-21435MEDIUMwebtransport-go CloseWithError can block indefinitelyEPSS 0.4%CVE-2026-66913MEDIUMZip Bomb in Lookyloo Capture Upload Allows Denial of ServiceEPSS 0.4%CVE-2026-66920HIGHPivotick - Stack Exhaustion Denial of Service via Deep or Cyclic Graph DataEPSS 0.4%CVE-2026-53530HIGHratex-parser panics on `\verb` with a multibyte delimiter (UTF-8 byte-boundary slice)EPSS 0.4%CVE-2025-32437HIGHAutoGPT has a DoS vulnerability in MediaDurationBlockEPSS 0.4%CVE-2026-19507HIGHRDK WebUI uncontrolled resource consumptionEPSS 0.4%CVE-2026-84235HIGHRockwell Automation 1756-ENBT Denial of Service VulnerabilityEPSS 0.4%CVE-2025-32422HIGHAutoGPT has a DoS vulnerability in FileStoreBlock with StepThroughItemsBlockEPSS 0.4%CVE-2025-32424HIGHAutoGPT has a DoS vulnerability in ScreenshotWebPageBlockEPSS 0.4%CVE-2026-2891HIGHPoly Voice Devices (CCX, Trio, Edge E) – Potential Denial of ServiceEPSS 0.4%CVE-2026-40016MEDIUMAttacker can upload a malicious Sieve script over ManageSieve service (or locally) to bypass configured CPU time limits for Sieve up to 130 EPSS 0.4%CVE-2025-58369MEDIUMfs2: Half-shutdown of socket during TLS handshake may result in spin loop on opposite sideEPSS 0.4%CVE-2025-5031LOWAckites KillWxapkg wxapkg File Decompression resource consumptionEPSS 0.4%CVE-2026-21577HIGHThis High severity DoS (Denial of Service) vulnerability was introduced in versions 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0EPSS 0.4%CVE-2026-83248HIGHVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). TheEPSS 0.4%CVE-2025-50098LOWVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.EPSS 0.4%CVE-2026-53531MEDIUMratex-parser has unbounded parser recursion that leads to stack overflow (process abort)EPSS 0.4%CVE-2024-13058MEDIUMAuthenticated, non-admin users can create storage pools via the sifi APIEPSS 0.4%CVE-2024-50953HIGHAn issue in XINJE XL5E-16T V3.7.2a allows attackers to cause a Denial of Service (DoS) via a crafted Modbus message.EPSS 0.4%