Falhas do tipo CWE-400

3.039 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2025-56352HIGHIn tinyMQTT commit 6226ade15bd4f97be2d196352e64dd10937c1962 (2024-02-18), the broker mishandles protocol violations during CONNECT packet paEPSS 0.3%CVE-2026-10156MEDIUMOpen5GS nf-instances Endpoint nnrf-handler.c handle_amf_info resource consumptionEPSS 0.3%CVE-2025-57440HIGHThe Blackmagic ATEM Mini Pro 2.7 exposes an undocumented Telnet service on TCP port 9993, which accepts unauthenticated plaintext commands fEPSS 0.3%CVE-2024-33259MEDIUMJerryscript commit cefd391 was discovered to contain a segmentation violation via the component scanner_seek at jerry-core/parser/js/js-scanEPSS 0.3%CVE-2024-53423MEDIUMAn issue in Open Network Foundation ONOS v2.7.0 allows attackers to cause a Denial of Service (DoS) via supplying crafted packets.EPSS 0.3%CVE-2024-42397MEDIUMUnauthenticated Denial-of-Service (DoS) Vulnerabilities in the AP Certificate Management Service Accessed by the PAPI ProtocolEPSS 0.3%CVE-2026-34673MEDIUMCAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)EPSS 0.3%CVE-2021-33135MEDIUMUncontrolled resource consumption in the Linux kernel drivers for Intel(R) SGX may allow an authenticated user to potentially enable denial EPSS 0.3%CVE-2025-49460MEDIUMZoom Workplace Clients - Argument InjectionEPSS 0.3%CVE-2026-60669MEDIUMVulnerability in the PeopleSoft Enterprise HCM Global Payroll Mexico product of Oracle PeopleSoft (component: Global Payroll for Mexico). EPSS 0.3%CVE-2026-96764MEDIUMkvcache-ai mooncake Regular Expression GetReplicaListByRegex allocation of resourcesEPSS 0.3%CVE-2026-61247MEDIUMVulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that EPSS 0.3%CVE-2025-66453MEDIUMRhino vulnerable high CPU usage and potential DoS when passing specific numbers to toFixed() functionEPSS 0.3%CVE-2021-3764—A memory leak flaw was found in the Linux kernel's ccp_run_aes_gcm_cmd() function that allows an attacker to cause a denial of service. The EPSS 0.3%CVE-2025-24199MEDIUMAn uncontrolled format string issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14EPSS 0.3%CVE-2026-61123MEDIUMVulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affeEPSS 0.3%CVE-2025-46304MEDIUMThe issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and iPadOS 26.2, macOS SeEPSS 0.3%CVE-2026-76696MEDIUMUnauthenticated Denial-of-Service (DoS) Vulnerability leads to Service Disruption in HPE Networking EdgeConnect SD-WAN GatewaysEPSS 0.3%CVE-2026-44247MEDIUMVolcano: Webhook server vulnerable to OOM due to unbounded HTTP request body sizeEPSS 0.3%CVE-2026-63457MEDIUMA potential denial of service vulnerability exists in HPE Integrated Lights-Out 6 (iLO 6) prior to v1.78.EPSS 0.3%