Falhas do tipo CWE-400

3.039 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2025-50861MEDIUMThe Lotus Cars Android app (com.lotus.carsdomestic.intl) 1.2.8 contains an exported component, PushDeepLinkActivity, which is accessible witEPSS 0.3%CVE-2024-50354MEDIUMOut-of-memory during deserialization with crafted inputsEPSS 0.3%CVE-2025-25208MEDIUMRhcl: authorino denial of service through authpolicy with sharedsecretref severityEPSS 0.3%CVE-2025-57751HIGHDenial-of-Service attack in pyLoad CNL Blueprint using dukpy.evaljsEPSS 0.3%CVE-2024-22588MEDIUMKwik commit 745fd4e2 does not discard unused encryption keys.EPSS 0.3%CVE-2026-22004MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0EPSS 0.3%CVE-2025-43706HIGHAn issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2400, 1580, 9110, W920,EPSS 0.3%CVE-2026-22002MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.EPSS 0.3%CVE-2026-21998MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.EPSS 0.3%CVE-2026-22005MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.EPSS 0.3%CVE-2026-87721HIGHDenial of Service via Exponential Backtracking in ANTLR Search Query Parser in Gerrit Code ReviewEPSS 0.3%CVE-2026-87722HIGHRegular Expression Denial of Service (ReDoS) in Search Query Predicates and REST Filter Endpoints in Gerrit Code ReviewEPSS 0.3%CVE-2026-86420MEDIUMImageMagick before 7.1.2-30 Denial of Service Memory BudgetEPSS 0.3%CVE-2025-8849MEDIUMDenial of Service in danny-avila/librechatEPSS 0.3%CVE-2022-29202MEDIUMDenial of service in TensorFlow due to lack of validation in `tf.ragged.constant`EPSS 0.3%CVE-2026-22239CRITICALEmail Sending Vulnerability in BLUVOYIXEPSS 0.3%CVE-2023-1654MEDIUMDenial of Service in gpac/gpacEPSS 0.3%CVE-2024-40841HIGHAn out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7. ProcesEPSS 0.3%CVE-2025-10470HIGHDenial-of-Service via Magic Link Authentication in WSO2 Identity Server Allows Service UnavailabilityEPSS 0.3%CVE-2025-63288HIGHIn Open5GS 2.7.6, AMF crashes when receiving an abnormal NGSetupRequest message, resulting in denial of service.EPSS 0.3%