Falhas do tipo CWE-400

3.030 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2026-43870HIGHApache Thrift: Node.js web_server.js multi-vulnerabilityEPSS 0.4%CVE-2023-32611MEDIUMG_variant_byteswap() can take a long time with some non-normal inputsEPSS 0.4%CVE-2025-30753MEDIUMVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.4%CVE-2023-52098HIGHDenial of Service (DoS) vulnerability in the DMS module. Successful exploitation of this vulnerability will affect availability.EPSS 0.4%CVE-2025-54575MEDIUMImageSharp Triggers an Infinite Loop in its GIF Decoder When Skipping Malformed Comment Extension BlocksEPSS 0.4%CVE-2023-49555MEDIUMAn issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expand_smacro function in the modules/preprocsEPSS 0.4%CVE-2023-5522MEDIUMMobile app freezes when receiving a post with hundreds of emojisEPSS 0.4%CVE-2026-7528HIGHUnauthenticated File Upload Vulnerability Allows Disk Space Exhaustion and Path Disclosure in Langflow OSSEPSS 0.4%CVE-2026-60647HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions tEPSS 0.4%CVE-2025-63561HIGHSummer Pearl Group Vacation Rental Management Platform prior to 1.0.2 is susceptible to a Slowloris-style Denial-of-Service (DoS) condition EPSS 0.4%CVE-2025-66863HIGHAn issue was discovered in function d_discriminator in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service viaEPSS 0.4%CVE-2025-9182HIGHDenial-of-service due to out-of-memory in the Graphics: WebRender componentEPSS 0.4%CVE-2024-5652MEDIUMIn Docker Desktop on Windows before v4.31.0 allows a user in the docker-users group to cause a Windows Denial-of-Service through the exec-path Docker daemon config option in Windows containers modeEPSS 0.4%CVE-2026-33123MEDIUMpypdf has inefficient decoding of array-based streamsEPSS 0.4%CVE-2026-47214HIGHDocling: Unsafe URI and Path Handling in HTML BackendEPSS 0.4%CVE-2026-54260MEDIUMWagtail: Denial of service via unbounded filter specs in the image previewEPSS 0.4%CVE-2026-33443HIGHMemory management error in Secure Access servers prior to 14.55EPSS 0.4%CVE-2025-0426MEDIUMA security issue was discovered in Kubernetes where a large number of container checkpoint requests made to the unauthenticated kubelet readEPSS 0.4%CVE-2026-10224MEDIUMNousResearch hermes-agent Webhook Endpoint feishu.py _handle_webhook_request resource consumptionEPSS 0.4%CVE-2026-84138HIGHDenial-of-service in the PDF Viewer componentEPSS 0.4%