Falhas do tipo CWE-400

3.039 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2026-73746LOWAuthenticated Denial of Service Vulnerability in HPE Networking Fabric Composer APIEPSS 0.3%CVE-2025-27829HIGHAn issue was discovered in Stormshield Network Security (SNS) 4.3.x before 4.3.35. If multicast streams are enabled on different interfaces,EPSS 0.3%CVE-2020-24089—An issue was discovered in ImfHpRegFilter.sys in IOBit Malware Fighter version 8.0.2, allows local attackers to cause a denial of service (DEPSS 0.3%CVE-2026-11790MEDIUM389-ds-base: 389-ds-base: pbkdf2 password storage plugin unbounded iteration count denial of serviceEPSS 0.3%CVE-2025-69199HIGHPterodactyl Wings's websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks under certain circumstancesEPSS 0.3%CVE-2026-81687HIGHopenssl_encrypt before 1.4.9 Denial of Service via KDFEPSS 0.3%CVE-2026-73759MEDIUMUnauthenticated Denial-of-Service Vulnerabilities in AOS-CXEPSS 0.3%CVE-2026-67220MEDIUMRabbitMQ: JMS topic exchange erl_scan atom exhaustionEPSS 0.3%CVE-2026-21588HIGHThis High severity DoS (Denial of Service) vulnerability was introduced in versions 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2,EPSS 0.3%CVE-2026-19645MEDIUMMultiple vulnerabilities in IBM MQ Agent imagesEPSS 0.3%CVE-2023-21061—Product: AndroidVersions: Android kernelAndroid ID: A-229255400References: N/AEPSS 0.3%CVE-2026-67227MEDIUMRabbitMQ: Atom exhaustion: to_atom on global-parameter :nameEPSS 0.3%CVE-2026-74903MEDIUMSiYuan before v3.7.4 Insufficient Access Control via spinBlockDOMEPSS 0.3%CVE-2026-42073MEDIUMOpenClaude's MCP OAuth Callback: State Check Bypass via error Param Leads to DoSEPSS 0.3%CVE-2026-73744LOWAuthenticated Denial of Service Vulnerability in HPE Networking Fabric Composer Web-Based Management InterfaceEPSS 0.3%CVE-2026-10705LOWdask HLL hyperloglog.py nunique_approx resource consumptionEPSS 0.3%CVE-2024-1816MEDIUMUncontrolled Resource Consumption in GitLabEPSS 0.3%CVE-2026-30955MEDIUMGokapi vulnerable to DoS in E2E Metadata ParserEPSS 0.3%CVE-2026-24738MEDIUMgmrtd ReadFile Vulnerable to Denial of Service via Excessive TLV Length ValuesEPSS 0.3%CVE-2026-102414MEDIUMpbkdf2 rehashes long passwords on every iteration, enabling denial of serviceEPSS 0.3%