Falhas do tipo CWE-400

3.039 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2026-87828MEDIUMSeraphinite Accelerator < 2.29.24 - Subscriber+ DoS via seraph_accel_State UpdateEPSS 0.3%CVE-2026-62518HIGHVulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions tEPSS 0.3%CVE-2025-43915MEDIUMIn Linkerd edge releases before edge-25.2.1, and Buoyant Enterprise for Linkerd releases 2.13.0–2.13.7, 2.14.0–2.14.10, 2.15.0–2.15.7, 2.16.EPSS 0.3%CVE-2026-22591HIGHFast DDS DDSSQLFilter Recursive Parser Stack Exhaustion (Remote DoS)EPSS 0.3%CVE-2026-72912MEDIUMCyberChef’s pretty-recipe parser vulnerable to client-side ReDoS / CPU exhaustion when parsing a malformed #recipe= URLEPSS 0.3%CVE-2026-6669MEDIUMUnbounded SCRAM iteration count causes CPU exhaustion in PgBouncerEPSS 0.3%CVE-2026-11926HIGHSecurity vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify AccessEPSS 0.3%CVE-2025-46115HIGHAn issue in open5gs v.2.7.3 allows a remote attacker to cause a denial of service via a crafted PDU Session Modification RequestEPSS 0.3%CVE-2025-6599MEDIUMAn uncontrolled resource consumption vulnerability in the web server of Zyxel DX3301-T0 firmware version 5.50(ABVY.6.3)C0 and earlier could EPSS 0.3%CVE-2026-77399MEDIUMicalendar: Denial of service via unbounded VALARM REPEAT expansionEPSS 0.3%CVE-2025-60458MEDIUMUxPlay 1.72 contains a double free vulnerability in its RTSP request handling. A specially crafted RTSP TEARDOWN request can trigger multiplEPSS 0.3%CVE-2026-10802MEDIUMkeystonejs keystone GraphQL API Endpoint output-field.ts resource consumptionEPSS 0.3%CVE-2026-10692MEDIUMjohnhuang316 code-index-mcp search_code_advanced is_safe_regex_pattern redosEPSS 0.3%CVE-2026-20188NONECisco Crosswork Network Controller and Cisco Network Services Orchestrator AdvisoryEPSS 0.3%CVE-2026-67222MEDIUMRabbitMQ: list_to_atom on auth_mechanism URI tokens in amqp_clientEPSS 0.3%CVE-2026-83465HIGHVulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versioEPSS 0.3%CVE-2022-46740MEDIUMThere is a denial of service vulnerability in the Wi-Fi module of the HUAWEI WS7100-20 Smart WiFi Router.Successful exploit could cause a deEPSS 0.3%CVE-2026-12600HIGHUncontrolled memory usage in Innodata Labs’ Poppler JPX decoderEPSS 0.3%CVE-2025-6712MEDIUMMongoDB Server may be susceptible to DoS due to Accumulated Memory AllocationEPSS 0.3%CVE-2026-0517MEDIUMDenial of Service in Secure Access Servers Prior to 14.20.EPSS 0.3%