Falhas do tipo CWE-400

3.026 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2025-41360HIGHUncontrolled resource consumption vulnerability in IDF and ZLFEPSS 0.4%CVE-2026-61816HIGHzbateson/mail-mime-parser has uncontrolled resource consumption (CPU/memory DoS) parsing untrusted MIMEEPSS 0.4%CVE-2025-6208MEDIUMUncontrolled Memory Consumption in run-llama/llama_indexEPSS 0.4%CVE-2026-61165HIGHVulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge). The supported version EPSS 0.4%CVE-2026-21941MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.EPSS 0.4%CVE-2026-29049MEDIUMmelange: unbounded HTTP download in `melange update-cache` can exhaust disk in CIEPSS 0.4%CVE-2026-21948MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.EPSS 0.4%CVE-2025-25193MEDIUMDenial of Service attack on windows app using NettyEPSS 0.4%CVE-2026-21952MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 9.0.0-9.5.0EPSS 0.4%CVE-2025-9464HIGHRockwell Automation ArmorStart® LT - Multiple Denial-of-Service VulnerabilitiesEPSS 0.4%CVE-2025-37161HIGHUnauthenticated Remote Denial-of-Service (DoS) Vulnerability in Web Management InterfaceEPSS 0.4%CVE-2026-25140HIGHapko affected by potential unbounded resource consumption in expandapk.ExpandApk on attacker-controlled .apk streamsEPSS 0.4%CVE-2026-10675MEDIUMBluetooth Mesh PB-ADV: invalidated provisioning link kept alive indefinitely, blocking (re)provisioning (DoS)EPSS 0.4%CVE-2026-47183MEDIUMZeroconf: Unbounded exception-dedup state retains packet buffers via traceback frame locals, enabling LAN-local memory exhaustionEPSS 0.4%CVE-2023-32665MEDIUMGvariant deserialisation does not match spec for non-normal dataEPSS 0.4%CVE-2026-28412MEDIUMTextream Vulnerable to Uncontrolled Resource Consumption (Denial of Service)EPSS 0.4%CVE-2025-55152MEDIUMoak: ReDoS in x-forwarded-proto and x-forwarded-for headersEPSS 0.4%CVE-2026-33382HIGHDenial of service via unbounded request body sizeEPSS 0.4%CVE-2025-54572MEDIUMRuby SAML DOS vulnerability with large SAML responseEPSS 0.4%CVE-2026-60719CRITICALVulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Supported versions that are affected areEPSS 0.4%