Falhas do tipo CWE-400

3.039 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2026-13108HIGHDimension Denial-of-ServiceEPSS 0.3%CVE-2026-12611HIGHA client may issue HTTP/2 requests to a Jetty server that result in blocking writes that are never unblocked, eventually causing all threadsEPSS 0.3%CVE-2026-23596MEDIUMUnauthenticated Improper Access Control in management API allows unauthorized service disruptionEPSS 0.3%CVE-2025-54149MEDIUMQsync CentralEPSS 0.3%CVE-2026-69249HIGHpython-cryptography: Duplicate self-signed intermediates can cause exponential path-buildingEPSS 0.3%CVE-2023-45167MEDIUMIBM AIX denial of serviceEPSS 0.3%CVE-2025-54151MEDIUMQsync CentralEPSS 0.3%CVE-2025-54150MEDIUMQsync CentralEPSS 0.3%CVE-2025-41361HIGHUncontrolled resource consumption vulnerability in IDF and ZLFEPSS 0.3%CVE-2026-86135HIGHDimension CSRF Vulnerability in Database Snapshot Creation Allows Denial of ServiceEPSS 0.2%CVE-2023-52602HIGHjfs: fix slab-out-of-bounds Read in dtSearchEPSS 0.2%CVE-2025-58767LOWREXML has a DoS condition when parsing malformed XML fileEPSS 0.2%CVE-2021-0092MEDIUMImproper access control in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable a denial of service vEPSS 0.2%CVE-2024-25452MEDIUMBento4 v1.6.0-640 was discovered to contain an out-of-memory bug via the AP4_UrlAtom::AP4_UrlAtom() function.EPSS 0.2%CVE-2026-49324MEDIUMIndian Scout Bobber 2025 WCM brute-forceEPSS 0.2%CVE-2021-46939MEDIUMtracing: Restructure trace_clock_global() to never blockEPSS 0.2%CVE-2026-60620MEDIUMVulnerability in the JD Edwards EnterpriseOne Configurator product of Oracle JD Edwards (component: Configuration Management). The supportEPSS 0.2%CVE-2024-39557HIGHJunos OS Evolved: MAC table changes cause a memory leakEPSS 0.2%CVE-2024-34035MEDIUMAn issue was discovered in O-RAN Near Realtime RIC H-Release. To trigger the crashing of the e2mgr, an adversary must flood the system with EPSS 0.2%CVE-2026-2405MEDIUMCWE-400 Uncontrolled Resource Consumption vulnerability exists that could cause excessive troubleshooting zip file creation and denial of seEPSS 0.2%