Falhas do tipo CWE-400

3.039 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2025-63811HIGHAn issue was discovered in dvsekhvalnov jose2go 1.5.0 thru 1.7.0 allowing an attacker to cause a Denial-of-Service (DoS) via crafted JSON WeEPSS 0.2%CVE-2026-11611MEDIUM389-ds-base: 389-ds-base: content sync plugin unbounded queue growth and race conditionsEPSS 0.2%CVE-2025-69198MEDIUMPterodactyl's improper resource locking allows raced queries to create more resources than allotedEPSS 0.2%CVE-2023-39328MEDIUMOpenjpeg: denail of service via crafted image fileEPSS 0.2%CVE-2024-32902HIGHRemote prevention of access to cellular service with no user interaction (for example, crashing the cellular radio service with a malformed EPSS 0.2%CVE-2025-6140MEDIUMspdlog pattern_formatter-inl.h scoped_padder resource consumptionEPSS 0.2%CVE-2024-26723HIGHlan966x: Fix crash when adding interface under a lagEPSS 0.2%CVE-2025-41226MEDIUMGuest Operations Denial-of-Service VulnerabilityEPSS 0.2%CVE-2025-31226MEDIUMA logic issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, tvOS 1EPSS 0.2%CVE-2026-86608HIGHWP Recipe Maker 9.8.0 - 10.8.1 - Unauthenticated DoS via Unbounded User Meta InsertionEPSS 0.2%CVE-2023-42941MEDIUMThe issue was addressed with improved checks. This issue is fixed in iOS 17.2 and iPadOS 17.2. An attacker in a privileged network position EPSS 0.2%CVE-2024-37535MEDIUMGNOME VTE before 0.76.3 allows an attacker to cause a denial of service (memory consumption) via a window resize escape sequence, a related EPSS 0.2%CVE-2025-44559MEDIUMAn issue in the Bluetooth Low Energy (BLE) stack of Realtek RTL8762E BLE SDK v1.4.0 allows attackers within Bluetooth range to cause a DeniaEPSS 0.2%CVE-2021-47238MEDIUMnet: ipv4: fix memory leak in ip_mc_add1_srcEPSS 0.2%CVE-2024-38384HIGHblk-cgroup: fix list corruption from reorder of WRITE ->lqueuedEPSS 0.2%CVE-2024-31146HIGHPCI device pass-through with shared resourcesEPSS 0.2%CVE-2025-30725MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.2%CVE-2024-31209MEDIUMOpenID Connect client Atom Exhaustion in provider configuration worker ets table locationEPSS 0.2%CVE-2026-82001MEDIUMAcrobat Reader | Uncontrolled Resource Consumption (CWE-400)EPSS 0.2%CVE-2024-22104MEDIUMOut-of-Bounds Write vulnerability in Jungo WinDriver before 12.5.1 allows local attackers to cause a Windows blue screen error and Denial ofEPSS 0.2%