Falhas do tipo CWE-400

3.039 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2026-10692MEDIUMjohnhuang316 code-index-mcp search_code_advanced is_safe_regex_pattern redosEPSS 0.3%CVE-2026-83465HIGHVulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versioEPSS 0.3%CVE-2022-46740MEDIUMThere is a denial of service vulnerability in the Wi-Fi module of the HUAWEI WS7100-20 Smart WiFi Router.Successful exploit could cause a deEPSS 0.3%CVE-2025-6712MEDIUMMongoDB Server may be susceptible to DoS due to Accumulated Memory AllocationEPSS 0.3%CVE-2026-12600HIGHUncontrolled memory usage in Innodata Labs’ Poppler JPX decoderEPSS 0.3%CVE-2026-100651HIGHvllm before 0.29.0 Denial of Service via Decoder Prompt Length BypassEPSS 0.3%CVE-2026-0517MEDIUMDenial of Service in Secure Access Servers Prior to 14.20.EPSS 0.3%CVE-2025-58349CRITICALAn issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330,EPSS 0.3%CVE-2025-31251MEDIUMThe issue was addressed with improved input sanitization. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5EPSS 0.3%CVE-2023-35925MEDIUMFastAsyncWorldEdit vulnerable to Uncontrolled Resource ConsumptionEPSS 0.3%CVE-2024-57412HIGHAn issue in SunOS Omnios v5.11 allows attackers to cause a Denial of Service (DoS) via repeatedly sending crafted TCP packets.EPSS 0.3%CVE-2026-22021MEDIUMVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). EPSS 0.3%CVE-2022-40480MEDIUMNordic Semiconductor, Microchip Technology NRF5340-DK DT100112 was discovered to contain an issue which allows attackers to cause a Denial oEPSS 0.3%CVE-2021-4022—A vulnerability was found in rizin. The bug involves an ELF64 binary for the HPPA architecture. When a specially crafted binarygets analysedEPSS 0.3%CVE-2026-22017MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.EPSS 0.3%CVE-2026-22009MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.EPSS 0.3%CVE-2026-102277MEDIUMbrace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU denial of serviceEPSS 0.3%CVE-2026-101911MEDIUMip-address: Address6 builds a parse diagnostic proportional to the input with no length bound, allowing a single long string to stall or crash the processEPSS 0.3%CVE-2026-59980MEDIUMhpack: Unbounded variable integer decoding can cause run-away computation on malformed inputEPSS 0.3%CVE-2025-8872HIGHA specially crafted packet can cause the OSFPv3 process to have high CPU utilization which may result in the OSFPv3 process being restartedEPSS 0.3%