Falhas do tipo CWE-400

3.036 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2026-27308LOWColdFusion | Uncontrolled Resource Consumption (CWE-400)EPSS 0.4%CVE-2026-60185MEDIUMVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affeEPSS 0.4%CVE-2026-27307LOWColdFusion | Uncontrolled Resource Consumption (CWE-400)EPSS 0.4%CVE-2025-50100LOWVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Thread Pooling). Supported versions that are affected are 8.0EPSS 0.4%CVE-2025-61301HIGHDenial-of-analysis in reporting/mongodb.py and reporting/jsondump.py in CAPEv2 (commit 52e4b43, on 2025-05-17) allows attackers who can submEPSS 0.4%CVE-2026-48187MEDIUMEmail with special content can lead to DoSEPSS 0.4%CVE-2021-32455MEDIUMSITEL CAP/PRX vulnerable to a denial of service attackEPSS 0.4%CVE-2026-76693HIGHUnauthenticated Denial-of-Service Vulnerability in HPE Networking EdgeConnect SD-WAN GatewaysEPSS 0.4%CVE-2025-53893HIGHFile Browser Vulnerable to Uncontrolled Memory Consumption Due to Oversized File ProcessingEPSS 0.4%CVE-2026-53493MEDIUMContainerd has image-pull DoS via crafted OCI index graph amplificationEPSS 0.4%CVE-2026-60667HIGHVulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Core). The supported version that EPSS 0.4%CVE-2025-52494HIGHAdacore Ada Web Server (AWS) before 25.2 is vulnerable to a denial-of-service (DoS) condition due to improper handling of SSL handshakes durEPSS 0.4%CVE-2026-40017MEDIUMAn attacker that can send mail to a user can craft a message header whose values are chosen to collide in an internal hash table, which makeEPSS 0.4%CVE-2026-83347MEDIUMVulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3. EasiEPSS 0.4%CVE-2026-40014MEDIUMAn attacker that can send mail to a user can craft a message header that makes the IMAP THREAD command consume CPU disproportionate to the sEPSS 0.4%CVE-2026-45149MEDIUMbrace-expansion: Large numeric range defeats documented `max` DoS protectionEPSS 0.4%CVE-2026-19587MEDIUMUncontrolled Resource Consumption vulnerability in Samsung Open Source rlottie allows Excessive Allocation.EPSS 0.4%CVE-2025-57317HIGHapidoc-core is the core parser library to generate apidoc result following the apidoc-spec. A Prototype Pollution vulnerability in the prePrEPSS 0.4%CVE-2025-60349HIGHAn issue was discovered in Prevx v3.0.5.220 allowing attackers to cause a denial of service via sending IOCTL code 0x22E044 to the pxscan.syEPSS 0.4%CVE-2026-55398MEDIUMMemory management vulnerability in Secure Access clientsEPSS 0.4%