Falhas do tipo CWE-400

3.036 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2026-33444MEDIUMMemory management vulnerability in Secure Access serversEPSS 0.4%CVE-2025-60349HIGHAn issue was discovered in Prevx v3.0.5.220 allowing attackers to cause a denial of service via sending IOCTL code 0x22E044 to the pxscan.syEPSS 0.4%CVE-2026-10691MEDIUMwonderwhy-er DesktopCommanderMCP start_search search-manager.ts redosEPSS 0.4%CVE-2026-55398MEDIUMMemory management vulnerability in Secure Access clientsEPSS 0.4%CVE-2026-67415MEDIUMRabbitMQ: Shovel Management Atom Exhaustion Allows Persistent Broker-Wide Denial of ServiceEPSS 0.4%CVE-2026-67226MEDIUMRabbitMQ: Admin-only atom exhaustion: PUT /api/users tags listEPSS 0.4%CVE-2025-71000HIGHAn issue in the flow.cuda.BoolTensor component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted input.EPSS 0.4%CVE-2024-48077HIGHNanoMQ v0.22.7 is vulnerable to Denial of Service (DoS) due to improper resource throttling. A crafted sequence of requests causes the recv-EPSS 0.4%CVE-2023-3614MEDIUMDenial of Service via specially crafted gif imageEPSS 0.4%CVE-2026-26066MEDIUMImageMagick has infinite loop when writing IPTCTEXT leads to denial of service via crafted profileEPSS 0.4%CVE-2024-57724MEDIUMlunasvg v3.0.0 was discovered to contain a segmentation violation via the component gray_record_cell.EPSS 0.3%CVE-2025-51741HIGHAn issue was discovered in Veal98 Echo Open-Source Community System 2.2 thru 2.3 allowing an unauthenticated attacker to cause the server toEPSS 0.3%CVE-2026-100527MEDIUMOpenClaw before 2026.8.2 Denial of Service via Browser RelayEPSS 0.3%CVE-2024-12579MEDIUMMinify HTML <= 2.1.10 - - Regular Expressions Denial of ServiceEPSS 0.3%CVE-2026-100572MEDIUMOpenClaw before 2026.8.1 Denial of Service via Rate LimitEPSS 0.3%CVE-2026-100571MEDIUMOpenClaw before 2026.8.1 SMS Webhook Rate Limit BypassEPSS 0.3%CVE-2026-16837HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.3%CVE-2024-12345MEDIUMINW Krbyyyzo Daily Huddle Site gbo.aspx resource consumptionEPSS 0.3%CVE-2025-67445MEDIUMTOTOLINK X5000R V9.1.0cu.2415_B20250515 contains a denial-of-service vulnerability in /cgi-bin/cstecgi.cgi. The CGI reads the CONTENT_LENGTHEPSS 0.3%CVE-2025-60638HIGHAn issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via crafted POST request to the NnssfEPSS 0.3%