Falhas do tipo CWE-400

3.036 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2026-55399MEDIUMResource exhaustion vulnerability in the Secure Access publisherEPSS 0.4%CVE-2026-54786LOWWasmtime: Leak in WASIp1 `fd_renumber` implementationEPSS 0.4%CVE-2026-57204MEDIUMpypdf: Missing stream length values ignore defined limitsEPSS 0.4%CVE-2024-31399MEDIUMExcessive platform resource consumption within a loop issue exists in Cybozu Garoon 5.0.0 to 5.15.2. If this vulnerability is exploited, proEPSS 0.4%CVE-2026-13149HIGHbrace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number oEPSS 0.4%CVE-2022-27640—A vulnerability has been identified in SIMATIC CP 442-1 RNA (All versions < V1.5.18), SIMATIC CP 443-1 RNA (All versions < V1.5.18). The affEPSS 0.4%CVE-2024-21658MEDIUMInsufficient control of region value length in discourse-calendarEPSS 0.4%CVE-2026-22540CRITICALDENIAL OF SERVICE VIA ARP PACKETSEPSS 0.4%CVE-2026-16376HIGHDenial-of-service in the Graphics: WebGPU componentEPSS 0.4%CVE-2025-2811MEDIUMGL.iNet GL-A1300 Slate Plus API redosEPSS 0.4%CVE-2025-66019MEDIUMpypdf manipulated LZWDecode streams can exhaust RAMEPSS 0.4%CVE-2026-21485HIGHiccDEV Undefined Behavior (UB) and Out of Memory in CIccProfile::LoadTag()EPSS 0.4%CVE-2021-3759—A memory overflow vulnerability was found in the Linux kernel’s ipc functionality of the memcg subsystem, in the way a user calls the semgetEPSS 0.4%CVE-2026-60182MEDIUMVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Clone Plugin). Supported versions that are affEPSS 0.4%CVE-2026-60184MEDIUMVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affeEPSS 0.4%CVE-2026-60186MEDIUMVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions EPSS 0.4%CVE-2026-33607MEDIUMAn attacker that has valid credentials can use IMAP LIST command to consume CPU. This can cause degradation or denial of service for IMAP. MEPSS 0.4%CVE-2026-60177MEDIUMVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Clone Plugin). Supported versions that are affEPSS 0.4%CVE-2026-60187MEDIUMVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affeEPSS 0.4%CVE-2026-47012MEDIUMVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affectEPSS 0.4%