Falhas do tipo CWE-400

3.039 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2025-55559HIGHAn issue was discovered TensorFlow v2.18.0. A Denial of Service (DoS) occurs when padding is set to 'valid' in tf.keras.layers.Conv2D.EPSS 0.2%CVE-2021-47371HIGHnexthop: Fix memory leaks in nexthop notification chain listenersEPSS 0.2%CVE-2021-21529LOWDell System Update (DSU) 1.9 and earlier versions contain a denial of service vulnerability. A local authenticated malicious user with low pEPSS 0.2%CVE-2024-0581MEDIUMUncontrolled Resource Consumption vulnerability on Sandsprite scdbgEPSS 0.2%CVE-2026-12319MEDIUMDenial-of-service in the Audio/Video: Playback componentEPSS 0.2%CVE-2022-26523MEDIUMThe socket connection handler in aswArPot.sys in the Avast and AVG Windows Anti Rootkit driver before 22.1 allows local attackers to executeEPSS 0.2%CVE-2025-27250MEDIUMUncontrolled resource consumption for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platform may allow EPSS 0.2%CVE-2025-9308MEDIUMyarnpkg Yarn request-manager.js setOptions redosEPSS 0.2%CVE-2025-27081MEDIUMHPE NonStop OSM Service Connection Suite, Denial of Service vulnerabilityEPSS 0.2%CVE-2025-11274MEDIUMOpen Asset Import Library Assimp Q3DLoader.cpp InternReadFile allocation of resourcesEPSS 0.2%CVE-2022-3698MEDIUM A denial of service vulnerability was reported in the Lenovo HardwareScanPlugin versions prior to 1.3.1.2 and  Lenovo Diagnostics versEPSS 0.2%CVE-2023-25949MEDIUMUncontrolled resource consumption in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enEPSS 0.2%CVE-2022-0353MEDIUM A denial of service vulnerability was reported in the Lenovo HardwareScanPlugin versions prior to 1.3.1.2 and  Lenovo Diagnostics versEPSS 0.2%CVE-2023-25769MEDIUMUncontrolled resource consumption in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated userEPSS 0.2%CVE-2025-29478MEDIUMAn issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the cfl_list_size in cfl_list.h:165.EPSS 0.2%CVE-2026-90554MEDIUMvLLM before 0.28.0 Denial of Service via audio extractionEPSS 0.2%CVE-2024-22102MEDIUMDenial of Service (DoS) vulnerability in Jungo WinDriver before 12.6.0 allows local attackers to cause a Windows blue screen error.EPSS 0.2%CVE-2024-13065MEDIUMBusiness Logic Error in Akinsoft's MyRezztaEPSS 0.2%CVE-2024-21823HIGHHardware logic with insecure de-synchronization in Intel(R) DSA and Intel(R) IAA for some Intel(R) 4th or 5th generation Xeon(R) processors EPSS 0.2%CVE-2026-3293MEDIUMsnowflakedb snowflake-jdbc JDBC URL SdkProxyRoutePlanner.java SdkProxyRoutePlanner redosEPSS 0.2%