Falhas do tipo CWE-400

3.039 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2024-31145HIGHerror handling in x86 IOMMU identity mappingEPSS 0.2%CVE-2022-46351MEDIUMA vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALAEPSS 0.2%CVE-2025-24151MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3.EPSS 0.2%CVE-2024-8939MEDIUMVllm: denials of service in vllm json web apiEPSS 0.2%CVE-2025-43295MEDIUMA denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 18.7 and iPadOS 18.7, macOS Sequoia 15.7, macOSEPSS 0.2%CVE-2021-0238MEDIUMJunos OS: MX Series: Executing CLI command repetitively may cause the system to run out of disk spaceEPSS 0.2%CVE-2026-20676MEDIUMThis issue was addressed through improved state management. This issue is fixed in Safari 26.3, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, EPSS 0.2%CVE-2025-6274MEDIUMWebAssembly wabt binary-reader-interp.cc OnDataCount resource consumptionEPSS 0.2%CVE-2024-57782MEDIUMAn issue in Docker-proxy v18.09.0 allows attackers to cause a denial of service.EPSS 0.2%CVE-2026-10668LOWHost-triggerable control-endpoint wedge (DoS) in Nuvoton NuMaker HSUSBD UDC driverEPSS 0.2%CVE-2024-35799MEDIUMdrm/amd/display: Prevent crash when disable streamEPSS 0.2%CVE-2022-28657HIGHApport does not disable python crash handler before entering chrootEPSS 0.2%CVE-2025-58436MEDIUMOpenPrinting CUPS slow client can halt cupsd, leading to a possible DoS attackEPSS 0.2%CVE-2026-15228HIGHKong Kubernetes Ingress Controller cluster-wide ingress configuration DoS via CA-certificate ID collisionEPSS 0.2%CVE-2025-6817MEDIUMHDF5 H5Centry.c H5C__load_entry resource consumptionEPSS 0.2%CVE-2024-0115MEDIUMNVIDIA CV-CUDA for Ubuntu 20.04, Ubuntu 22.04, and Jetpack contains a vulnerability in Python APIs where a user may cause an uncontrolled reEPSS 0.2%CVE-2026-16543HIGHKong Operator cluster-wide ingress configuration DoS via embedded KIC CA-certificate ID collisionEPSS 0.2%CVE-2026-6777MEDIUMOther issue in the Networking: DNS componentEPSS 0.2%CVE-2026-12325MEDIUMDenial-of-service in the Graphics: ImageLib componentEPSS 0.2%CVE-2021-47284MEDIUMisdn: mISDN: netjet: Fix crash in nj_probe:EPSS 0.2%