Falhas do tipo CWE-400

3.039 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2026-57962MEDIUMDenial-of-service via malicious LDAP address-book serverEPSS 0.3%CVE-2025-70059HIGHAn issue pertaining to CWE-400: Uncontrolled Resource Consumption was discovered in YMFE yapi v1.12.0 and allows attackers to cause a denialEPSS 0.3%CVE-2026-6060MEDIUMPossible DoS via SQL BoxEPSS 0.3%CVE-2021-20265—A flaw was found in the way memory resources were freed in the unix_stream_recvmsg function in the Linux kernel when a signal was pending. TEPSS 0.3%CVE-2026-44167HIGHphpseclib: CVE-2024-27355 mitigation bypass — OID amplification DoS in ASN1::decodeOID()EPSS 0.3%CVE-2026-61192MEDIUMVulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version tEPSS 0.3%CVE-2026-83251MEDIUMVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). TheEPSS 0.3%CVE-2026-87267MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.3%CVE-2025-55029HIGHMalicious scripts could spam popups for denial of service attacksEPSS 0.3%CVE-2020-15100LOWUncontrolled Resource Consumption in freewvsEPSS 0.3%CVE-2026-73057HIGHstoatchat before 0.15.0 Uncapped SVG Rendering Denial of ServiceEPSS 0.3%CVE-2025-6714HIGHIncorrect Handling of incomplete data may prevent mongoS from Accepting New ConnectionsEPSS 0.3%CVE-2024-25132MEDIUMOpenshift-dedicated: hive: hibernation controller denial of serviceEPSS 0.3%CVE-2025-56233HIGHOpenindiana, kernel SunOS 5.11 has a denial of service vulnerability. For the processing of TCP packets with RST or SYN flag set, OpenindianEPSS 0.3%CVE-2025-56234HIGHAT_NA2000 from Nanda Automation Technology vendor has a denial-of-service vulnerability. For the processing of TCP RST packets, PLC AT_NA200EPSS 0.3%CVE-2025-53371CRITICALDiscordNotifications allows DOS, SSRF, and possible RCE through requests to user-controlled URLsEPSS 0.3%CVE-2026-32686MEDIUMUnbounded exponent in decimal enables unauthenticated DoSEPSS 0.3%CVE-2026-73754MEDIUMAuthenticated Denial-of-Service Vulnerabilities in the Command Line Interface of AOS-CXEPSS 0.3%CVE-2025-49000LOWInvenTree has uncontrolled memory allocation via built-in label-sheet pluginEPSS 0.3%CVE-2025-58451HIGHCattown Vulnerable to Inefficient Regular Expression Complexity and Uncontrolled Resource ConsumptionEPSS 0.3%