Falhas do tipo CWE-400

3.036 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2026-20080MEDIUMCisco IEC6400 Edge Compute Appliance SSH Denial of Service VulnerabilityEPSS 0.4%CVE-2025-54884HIGHVision UI security-kit.js: Potential Uncontrolled Resource Allocation VulnerabilityEPSS 0.4%CVE-2025-43796HIGHLiferay Portal 7.4.0 through 7.4.3.101, and Liferay DXP 2023.Q3.0 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA though update 35 doEPSS 0.4%CVE-2025-48053HIGHDiscourse vulnerable to DoS via large URL payload in PM to a botEPSS 0.4%CVE-2026-22542CRITICALDENIAL OF SERVICE FOR CONCURRENT CONNECTIONS ON TELNETEPSS 0.4%CVE-2023-38043HIGHA vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attackerEPSS 0.4%CVE-2026-60303MEDIUMVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.EPSS 0.4%CVE-2026-60410MEDIUMVulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The suppoEPSS 0.4%CVE-2026-33754MEDIUMWazuh: Unauthenticated cluster packet length leads to uncontrolled memory allocation (remote DoS)EPSS 0.4%CVE-2026-60233MEDIUMVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 15.EPSS 0.4%CVE-2026-83416MEDIUMVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.EPSS 0.4%CVE-2021-44527—A vulnerability found in UniFi Switch firmware Version 5.43.35 and earlier allows a malicious actor who has already gained access to the netEPSS 0.4%CVE-2022-22155MEDIUMJunos OS: ACX5448: FPC memory leak due to IPv6 neighbor flapsEPSS 0.4%CVE-2026-81725MEDIUMNLTK before 3.10.3 Regular Expression Denial of Service via Pl196xCorpusReaderEPSS 0.4%CVE-2025-13466MEDIUMbody-parser vulnerable to denial of service when url encoding is usedEPSS 0.4%CVE-2026-60411MEDIUMVulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: ttcserver). The supported versiEPSS 0.4%CVE-2021-22553MEDIUMHeap Memory exhaustion in GerritEPSS 0.4%CVE-2026-21950MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 9.0.0-9.EPSS 0.4%CVE-2026-21949MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 9.0.0-9.EPSS 0.4%CVE-2026-57204MEDIUMpypdf: Missing stream length values ignore defined limitsEPSS 0.4%