Falhas do tipo CWE-400

3.026 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2025-67731HIGHServify Express does not enforce rate limiting when parsing JSONEPSS 0.4%CVE-2025-54604HIGHBitcoin Core through 29.0 allows Uncontrolled Resource Consumption (issue 1 of 2).EPSS 0.4%CVE-2025-54605HIGHBitcoin Core through 29.0 allows Uncontrolled Resource Consumption (issue 2 of 2).EPSS 0.4%CVE-2025-56264HIGHThe /api/comment endpoint in zhangyd-c OneBlog 2.3.9 contains a denial-of-service vulnerability.EPSS 0.4%CVE-2026-60846MEDIUMVulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versioEPSS 0.4%CVE-2022-2962HIGHA DMA reentrancy issue was found in the Tulip device emulation in QEMU. When Tulip reads or writes to the rx/tx descriptor or copies the rx/EPSS 0.4%CVE-2023-50121MEDIUMAutel EVO NANO drone flight control firmware version 1.6.5 is vulnerable to denial of service (DoS).EPSS 0.4%CVE-2026-27859MEDIUMA mail message containing excessive amount of RFC 2231 MIME parameters causes LMTP to use too much CPU. A suitably formatted mail message caEPSS 0.4%CVE-2026-83459MEDIUMVulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-media-multipart). Supported versions that are affectedEPSS 0.4%CVE-2025-67835MEDIUMPaessler PRTG Network Monitor before 25.4.114 allows Denial-of-Service (DoS) by an authenticated attacker via the Notification Contacts funcEPSS 0.4%CVE-2026-53596MEDIUMFreeScout has unrestricted file upload without rate limiting that leads to resource exhaustion (DoS)EPSS 0.4%CVE-2026-83458MEDIUMVulnerability in the Helidon product of Oracle Fusion Middleware (component: JSON). Supported versions that are affected are 4.0.0-4.5.4. EEPSS 0.4%CVE-2026-19475MEDIUMSQL Data Source Plugin: OOM DoS via $__timeGroup macroEPSS 0.4%CVE-2026-51106CRITICALAn issue in TokTok qTox v1.18.4 allows a local attacker to cause a denial of service via the src/persistence/serialize.cpp componentEPSS 0.4%CVE-2026-19113MEDIUMUnauthenticated denial of service via unbounded request body processingEPSS 0.4%CVE-2026-59315MEDIUMSpring Cloud Config Monitor Denial of ServiceEPSS 0.4%CVE-2024-57074HIGHA prototype pollution in the lib.merge function of xe-utils v3.5.31 allows attackers to cause a Denial of Service (DoS) via supplying a crafEPSS 0.4%CVE-2025-71418MEDIUMPocketMine-MP before 5.25.2 Denial of Service via explodeEPSS 0.4%CVE-2024-57085HIGHA prototype pollution in the function deepMerge of @stryker-mutator/util v8.6.0 allows attackers to cause a Denial of Service (DoS) via suppEPSS 0.4%CVE-2024-24424HIGHA reachable assertion in the decode_access_point_name_ie function of Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2EPSS 0.4%