Falhas do tipo CWE-400

3.026 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2026-61109MEDIUMVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: JSON). Supported versions that are affected arEPSS 0.4%CVE-2026-34270MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affectEPSS 0.4%CVE-2026-34308MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: JSON). Supported versions that are affected are 8.0.0-8.0.45,EPSS 0.4%CVE-2026-61093MEDIUMVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affectEPSS 0.4%CVE-2026-60404MEDIUMVulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The suppoEPSS 0.4%CVE-2026-60403MEDIUMVulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The suppoEPSS 0.4%CVE-2026-34303MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.EPSS 0.4%CVE-2025-25341HIGHA vulnerability exists in the libxmljs 1.0.11 when parsing a specially crafted XML document. Accessing the internal _ref property on entity_EPSS 0.4%CVE-2026-61194MEDIUMVulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Core). The supported version thatEPSS 0.4%CVE-2026-60718MEDIUMVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: JSON). Supported versions that are affected arEPSS 0.4%CVE-2026-88798MEDIUMReally Simple Security (Free) < 9.8.3 - Unauthenticated Unbounded Option Growth via Spoofed Client IP HeaderEPSS 0.4%CVE-2026-28375MEDIUMGrafana Testdata datasource can issue unbounded memory allocationsEPSS 0.4%CVE-2026-61160HIGHVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience MaEPSS 0.4%CVE-2026-5755MEDIUMDenial of service via crafted TIFF file uploadEPSS 0.4%CVE-2026-63136MEDIUMUncontrolled Resource Consumption in Elasticsearch Leading to Denial of ServiceEPSS 0.4%CVE-2026-9602MEDIUMMattermost Desktop App crashes when malformed arguments are provided to some exposed IPC methodsEPSS 0.4%CVE-2026-27879MEDIUMQuery resampling can cause unbounded memory allocationsEPSS 0.4%CVE-2026-49090MEDIUMUncontrolled Resource Consumption in Elasticsearch Leading to Denial of ServiceEPSS 0.4%CVE-2026-63263MEDIUMUncontrolled Resource Consumption in Elasticsearch Leading to Denial of ServiceEPSS 0.4%CVE-2026-35441MEDIUMDirectus Affected by GraphQL Alias Amplification Denial-of-Service Due to Missing Query Cost/Complexity LimitsEPSS 0.4%