Falhas do tipo CWE-400

3.026 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2026-47046HIGHVulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Easily exploitableEPSS 0.4%CVE-2026-46866HIGHVulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen). Supported veEPSS 0.4%CVE-2024-56528HIGHThis vulnerability affects Snowplow Collector 3.x before 3.3.0 (unless it’s set up behind a reverse proxy that establishes payload limits). EPSS 0.4%CVE-2025-50103MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: LDAP Auth). Supported versions that are affected arEPSS 0.4%CVE-2024-47212HIGHAn issue was discovered in Iglu Server 0.13.0 and below. It involves sending very large payloads to a particular API endpoint of Iglu ServerEPSS 0.4%CVE-2025-20058HIGHBIG-IP message routing vulnerabilityEPSS 0.4%CVE-2026-57224MEDIUMSuricata dhcp: unbounded transactions in unidirectional traffic can lead to resource exhaustionEPSS 0.4%CVE-2024-47535MEDIUMDenial of Service attack on windows app using NettyEPSS 0.4%CVE-2025-21087HIGHTMM VulnerabilityEPSS 0.4%CVE-2024-29153HIGHA vulnerability was discovered in Samsung Mobile Processor, Wearable Processor, and Modems with versions Exynos 9820, Exynos 9825, Exynos 98EPSS 0.4%CVE-2024-24943MEDIUMIn JetBrains Toolbox App before 2.2 a DoS attack was possible via a malicious SVG imageEPSS 0.4%CVE-2023-1071LOWAn issue has been discovered in GitLab affecting all versions from 15.5 before 15.8.5, all versions starting from 15.9 before 15.9.4, all veEPSS 0.4%CVE-2022-40513HIGHUncontrolled resource consumption in WLAN Firmware.EPSS 0.4%CVE-2024-24975LOW Denial of Service for mobile app users due to automatic code highlightingEPSS 0.4%CVE-2023-21339HIGHIn Minikin, there is a possible way to trigger ANR by showing a malicious message due to resource exhaustion. This could lead to remote deniEPSS 0.4%CVE-2026-47881MEDIUMDenial of Service in Spring Batch FlatFileItemReader via Malformed Input FileEPSS 0.4%CVE-2026-33445HIGHMemory management vulnerability in Secure Access serversEPSS 0.4%CVE-2025-0114HIGHPAN-OS: Denial of Service (DoS) in GlobalProtectEPSS 0.4%CVE-2025-55102HIGHA denial-of-service vulnerability exists in the NetX IPv6 component functionality of Eclipse ThreadX NetX Duo. A specially crafted network pEPSS 0.4%CVE-2021-0257MEDIUMJunos OS: MX Series, EX9200 Series: Trio-based MPCs memory leak in VPLS with integrated routing and bridging (IRB) interfaceEPSS 0.4%