Falhas do tipo CWE-400

3.027 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2025-54572MEDIUMRuby SAML DOS vulnerability with large SAML responseEPSS 0.4%CVE-2026-93590MEDIUMImageMagick before 7.1.2-31 Policy Bypass in UHDR encoderEPSS 0.4%CVE-2023-45150MEDIUMInviting excessive long email addresses to a calendar event makes the Nextcloud server unresponsiveEPSS 0.4%CVE-2025-50057MEDIUMExtension - rsjoomla.com - DOS vulnerability RSFiles! component 1.16.3-1.17.7 for JoomlaEPSS 0.4%CVE-2025-62260HIGHLiferay Portal 7.4.0 through 7.4.3.99, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and EPSS 0.4%CVE-2023-1981MEDIUMA vulnerability was found in the avahi library. This flaw allows an unprivileged user to make a dbus call, causing the avahi daemon to crashEPSS 0.4%CVE-2025-48041HIGHSSH_FXP_OPENDIR may Lead to Exhaustion of File HandlesEPSS 0.4%CVE-2025-48039MEDIUMUnverified Paths can Cause Excessive Use of System ResourcesEPSS 0.4%CVE-2025-11681HIGHDenial of Service condition in M-Files ServerEPSS 0.4%CVE-2025-48038MEDIUMUnverified File Handles can Cause Excessive Use of System ResourcesEPSS 0.4%CVE-2025-32436HIGHAutoGPT has a DoS vulnerability in AddAudioToVideoBlockEPSS 0.4%CVE-2026-60582HIGHVulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). The supported versioEPSS 0.4%CVE-2021-1564MEDIUMCisco Video Surveillance 7000 Series IP Cameras Cisco Discovery and Link Layer Discovery Protocol Memory Leak VulnerabilitiesEPSS 0.4%CVE-2021-1563MEDIUMCisco Video Surveillance 7000 Series IP Cameras Cisco Discovery and Link Layer Discovery Protocol Memory Leak VulnerabilitiesEPSS 0.4%CVE-2026-76400MEDIUMDenial of Service (DoS) through the REST API in Splunk Connect for KafkaEPSS 0.4%CVE-2026-40019MEDIUMAn unauthenticated attacker can send a truncated quoted argument to the ManageSieve login process, which makes it spin in an infinite loop cEPSS 0.4%CVE-2021-0292MEDIUMJunos OS Evolved: Memory leak in arpd or ndp processes can lead to Denial of Service (DoS)EPSS 0.4%CVE-2025-6297HIGHdpkg-deb: Fix cleanup for control member with restricted directoriesEPSS 0.4%CVE-2022-31030MEDIUMcontainerd CRI plugin: Host memory exhaustion through ExecSyncEPSS 0.4%CVE-2023-32611MEDIUMG_variant_byteswap() can take a long time with some non-normal inputsEPSS 0.4%