Falhas do tipo CWE-400

3.039 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2025-49000LOWInvenTree has uncontrolled memory allocation via built-in label-sheet pluginEPSS 0.3%CVE-2025-58451HIGHCattown Vulnerable to Inefficient Regular Expression Complexity and Uncontrolled Resource ConsumptionEPSS 0.3%CVE-2026-100648MEDIUMvllm before 0.29.0 Uncontrolled Resource Consumption via Audio DecodingEPSS 0.3%CVE-2025-62477MEDIUMVulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Remote Replication). The supported version thaEPSS 0.3%CVE-2026-44242LOWMicronaut Framework: Unbounded bundleCache in ResourceBundleMessageSource Allows Memory Exhaustion via Accept-Language HeaderEPSS 0.3%CVE-2025-62478MEDIUMVulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Object Store). The supported version that is aEPSS 0.3%CVE-2025-62476MEDIUMVulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Remote Replication). The supported version thaEPSS 0.3%CVE-2026-83968HIGHWindows Biometric Service Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2025-62475MEDIUMVulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Core). The supported version that is affected EPSS 0.3%CVE-2026-66073MEDIUMRabbitMQ: Atom table exhaustion via management API node fieldEPSS 0.3%CVE-2025-49494HIGHAn issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 2100, 1280, 2200, 1330, 1380, 1480, 9110, Modem 51EPSS 0.3%CVE-2006-5648MEDIUMUbuntu Linux 6.10 for the PowerPC (PPC) allows local users to cause a denial of service (resource consumption) by using the (1) sys_get_robuEPSS 0.3%CVE-2026-66072MEDIUMRabbitMQ: Atom table exhaustion via stream `chunk_selector`EPSS 0.3%CVE-2026-67238HIGHRabbitMQ: Atom-table exhaustion via reply-to queue name decodingEPSS 0.3%CVE-2026-39396LOWOpenBao has Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)EPSS 0.3%CVE-2026-23824HIGHUnauthenticated Denial-of-Service via Crafted Messages in a Network Protocol Handling ComponentEPSS 0.3%CVE-2023-38210MEDIUMOther | Uncontrolled Resource Consumption (CWE-400)EPSS 0.3%CVE-2026-47734MEDIUMDulwich has unbounded memory allocation in receive-pack from crafted thin packsEPSS 0.3%CVE-2025-50861MEDIUMThe Lotus Cars Android app (com.lotus.carsdomestic.intl) 1.2.8 contains an exported component, PushDeepLinkActivity, which is accessible witEPSS 0.3%CVE-2026-60213MEDIUMVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.EPSS 0.3%