Falhas do tipo CWE-400

3.039 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2025-69654HIGHA crafted JavaScript input executed with the QuickJS release 2025-09-13, fixed in commit fcd33c1afa7b3028531f53cd1190a3877454f6b3 (2025-12-1EPSS 0.3%CVE-2024-14036HIGHDräger Core 1.0.5 Denial of Service via Malformed SDC MessageEPSS 0.3%CVE-2026-29776LOWFreeRDP has an Integer Underflow in update_read_cache_bitmap_order Function of FreeRDP's Core LibraryEPSS 0.3%CVE-2026-74797LOWOpenTofu before 1.11.4 Denial of Service via malicious zipEPSS 0.3%CVE-2026-44456MEDIUMHono: bodyLimit() can be bypassed for chunked / unknown-length requestsEPSS 0.3%CVE-2026-81723MEDIUMNLTK before 3.10.3 Quadratic CPU Exhaustion via XMLCorpusViewEPSS 0.3%CVE-2026-19401HIGHRemote UDP DoS by sending multiple DNS Cookie optionsEPSS 0.3%CVE-2026-17465MEDIUMMultiple Vulnerabilities in IBM Concert SoftwareEPSS 0.3%CVE-2025-7105MEDIUMDenial of Service via JavaScript Memory Overflow in danny-avila/librechatEPSS 0.3%CVE-2025-61155MEDIUMThe GameDriverX64.sys kernel-mode anti-cheat driver (v7.23.4.7 and earlier) contains an access control vulnerability in one of its IOCTL hanEPSS 0.3%CVE-2024-54113MEDIUMProcess residence vulnerability in abnormal scenarios in the print module Impact: Successful exploitation of this vulnerability may affect pEPSS 0.3%CVE-2025-54324HIGHAn issue was discovered in NAS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330EPSS 0.3%CVE-2025-65122HIGHRegex Denial of Service in youtube-regex npm package through version 1.0.5.EPSS 0.3%CVE-2024-44154MEDIUMA memory initialization issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7. ProceEPSS 0.3%CVE-2025-56352HIGHIn tinyMQTT commit 6226ade15bd4f97be2d196352e64dd10937c1962 (2024-02-18), the broker mishandles protocol violations during CONNECT packet paEPSS 0.3%CVE-2024-31994MEDIUMMealie vulnerable to a DoS in recipe image importer (GHSL-2023-228)EPSS 0.3%CVE-2026-100558HIGHOpenClaw before 2026.8.1 Resource Exhaustion via WebSocket UpgradeEPSS 0.3%CVE-2025-59440HIGHAn issue was discovered in USIM in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 133EPSS 0.3%CVE-2026-67228MEDIUMRabbitMQ: Atom exhaustion: to_atom on runtime-parameter componentEPSS 0.3%CVE-2024-24769LOWVantage6: No limit on emails sent for password/MFA resetEPSS 0.3%