Falhas do tipo CWE-400

3.026 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2026-47021MEDIUMVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). SEPSS 0.4%CVE-2026-82300MEDIUMUncontrolled Resource Consumption in Elasticsearch Leading to Denial of ServiceEPSS 0.4%CVE-2026-94397MEDIUMUncontrolled Resource Consumption in Elasticsearch Leading to denial of serviceEPSS 0.4%CVE-2026-36724MEDIUMAn uncaught exception in the /application/job/update/{id} endpoint of FastapiAdmin v2.2.0 allows authenticated attackers with the module_tasEPSS 0.4%CVE-2026-94400MEDIUMUncontrolled Resource Consumption in Kibana Leading to denial of serviceEPSS 0.4%CVE-2025-26783HIGHAn issue was discovered in RRC in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 2100, 1280, 2200, 1330, 1380, 1480, 2400, WEPSS 0.4%CVE-2026-87106MEDIUMConsul vulnerable to a denial of service in the native RPC listenerEPSS 0.4%CVE-2026-52687MEDIUMAn attacker that has valid credentials can select a compression algorithm for the IMAP connection whose decompression state requires a largeEPSS 0.4%CVE-2025-53046MEDIUMVulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Analytics). The supported version that is affeEPSS 0.4%CVE-2026-16265MEDIUMWP Maps < 4.9.7 - Subscriber+ Denial of ServiceEPSS 0.4%CVE-2026-27878MEDIUMTempo TraceQL query with exemplar hint could result in unbounded memory usageEPSS 0.4%CVE-2026-24215MEDIUMNVIDIA Triton Inference Server contains a vulnerability in the DALI backend, where an attacker could cause uncontrolled resource consumptionEPSS 0.4%CVE-2025-55560HIGHAn issue in pytorch v2.7.0 can lead to a Denial of Service (DoS) when a PyTorch model consists of torch.Tensor.to_sparse() and torch.Tensor.EPSS 0.4%CVE-2026-94399MEDIUMUncontrolled Resource Consumption in Elasticsearch Leading to denial of serviceEPSS 0.4%CVE-2026-61070MEDIUMVulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Cash Management). The supEPSS 0.4%CVE-2026-94396MEDIUMUncontrolled Resource Consumption in Elasticsearch Leading to denial of serviceEPSS 0.4%CVE-2026-94398MEDIUMUncontrolled Resource Consumption in Elasticsearch Leading to denial of serviceEPSS 0.4%CVE-2026-39197MEDIUMAn issue in the /util/http/prelude.rs endpoint of Datadog, Inc Vector v0.54.0 allows attackers to cause a Denial of Service (DoS) via a crafEPSS 0.4%CVE-2026-82294MEDIUMUncontrolled Resource Consumption in Elasticsearch Leading to Denial of ServiceEPSS 0.4%CVE-2024-47212HIGHAn issue was discovered in Iglu Server 0.13.0 and below. It involves sending very large payloads to a particular API endpoint of Iglu ServerEPSS 0.4%