Falhas do tipo CWE-400

3.036 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2026-22228MEDIUMImproper Input Validation Leading to DoS on TP-Link Archer BE230EPSS 0.3%CVE-2014-2343—Triangle MicroWorks SCADA Data Gateway Resource ExhaustionEPSS 0.3%CVE-2025-65947HIGHthread-amount is Vulnerable to Resource Exhaustion (Memory and Handle Leaks) on Windows and macOSEPSS 0.3%CVE-2025-30188HIGHMalicious or unintentional API requests can be used to add significant amount of data to caches. Caches may evict information that is requirEPSS 0.3%CVE-2025-64388CRITICALDenial of service through specific packetsEPSS 0.3%CVE-2025-7579MEDIUMchinese-poetry server.js redosEPSS 0.3%CVE-2025-70047HIGHAn issue pertaining to CWE-400: Uncontrolled Resource Consumption was discovered in Nexusoft NexusInterface v3.2.0-beta.2.EPSS 0.3%CVE-2024-8892MEDIUMUncontrolled Resource Consumption vulnerability on CIRCUTOR TCP2RS+EPSS 0.3%CVE-2026-17463MEDIUMIBM® Db2® could allow a remote authenticated attacker to cause a denial of service due to uncontrolled resource consumptionEPSS 0.3%CVE-2020-18770—An issue was discovered in function zzip_disk_entry_to_file_header in mmapped.c in zziplib 0.13.69, which will lead to a denial-of-service.EPSS 0.3%CVE-2026-22740MEDIUMSpring Framework DoS with Multipart Temp Files in WebFluxEPSS 0.3%CVE-2026-100661HIGHNetty HTTP/3 QPACK Prefixed Integer DoS via Unbounded AccumulationEPSS 0.3%CVE-2026-100662HIGHNetty HTTP/3 QPACK encoder-stream unbounded memory exhaustion DoSEPSS 0.3%CVE-2026-8856HIGHIBM HTTP Server is affected by multiple vulnerabilitiesEPSS 0.3%CVE-2025-29490MEDIUMlibming v0.4.8 was discovered to contain a segmentation fault via the decompileCALLMETHOD function. This vulnerability allows attackers to cEPSS 0.3%CVE-2025-65781HIGHAn issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Attachment upload API treats the AEPSS 0.3%CVE-2026-66071MEDIUMRabbitMQ: Atom exhaustion: OAuth2 JWT tag: scope valuesEPSS 0.3%CVE-2026-22745MEDIUMCVE-2026-22745 : Denial of service in static resource handling on Windows platformsEPSS 0.3%CVE-2024-7294HIGHUncontrolled resource consumption of anonymous endpointsEPSS 0.3%CVE-2026-67408HIGHRabbitMQ: Stream Management Super-Stream Binding Keys Allocation Allows Low-Privilege Node Denial of ServiceEPSS 0.3%