Falhas do tipo CWE-400

3.039 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2026-34678MEDIUMCAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)EPSS 0.3%CVE-2026-47904MEDIUMCAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)EPSS 0.3%CVE-2026-48434MEDIUMCAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)EPSS 0.3%CVE-2026-47905MEDIUMCAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)EPSS 0.3%CVE-2026-48443MEDIUMCAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)EPSS 0.3%CVE-2026-23809MEDIUMMAC Address Spoofing leads to Inter-BSSID Isolation Bypass Resulting in Traffic RedirectionEPSS 0.3%CVE-2026-34677MEDIUMCAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)EPSS 0.3%CVE-2026-47902MEDIUMCAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)EPSS 0.3%CVE-2025-8449MEDIUMCWE-400: Uncontrolled Resource Consumption vulnerability exists that could cause a denial of service when an authenticated user sends a specEPSS 0.3%CVE-2026-48357MEDIUMCAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)EPSS 0.3%CVE-2021-47313HIGHcpufreq: CPPC: Fix potential memleak in cppc_cpufreq_cpu_initEPSS 0.3%CVE-2026-100542LOWOpenClaw before 2026.8.1 Extraction Limit Bypass via tar.bz2EPSS 0.3%CVE-2026-47262MEDIUMcontainerd image-triggered runtime DoS via unbounded group parsingEPSS 0.3%CVE-2025-37148MEDIUMKernel Panic triggered by Modified Ethernet Frames leads to Denial of Service VulnerabilityEPSS 0.3%CVE-2021-47010HIGHnet: Only allow init netns to set default tcp cong to a restricted algoEPSS 0.3%CVE-2024-44183MEDIUMA logic error was addressed with improved error handling. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS SequoEPSS 0.3%CVE-2026-50171HIGHAngular: Denial of Service (DoS) via OOM in Number Formatting (digitsInfo)EPSS 0.3%CVE-2023-52672HIGHpipe: wakeup wr_wait after setting max_usageEPSS 0.3%CVE-2020-35534—In LibRaw, there is a memory corruption vulnerability within the "crxFreeSubbandData()" function (libraw\src\decoders\crx.cpp) when processiEPSS 0.3%CVE-2023-42983MEDIUMProcessing a file may lead to a denial-of-service or potentially disclose memory contents. This issue is fixed in macOS 14. The issue was adEPSS 0.3%