Falhas do tipo CWE-400

3.039 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2026-71870MEDIUMpypdf: Possible large memory usage for large /ToUnicode streamsEPSS 0.2%CVE-2025-29477MEDIUMAn issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the function consume_event.EPSS 0.2%CVE-2026-82735MEDIUMMatch regex runs on over-length input in Ash.Type.String, enabling regex denial of serviceEPSS 0.2%CVE-2023-20911HIGHIn addPermission of PermissionManagerServiceImpl.java , there is a possible failure to persist permission settings due to resource exhaustioEPSS 0.2%CVE-2026-82742MEDIUMAsh.Filter.Runtime materializes a combinatorial cross-product over to-many relationships, exhausting memoryEPSS 0.2%CVE-2026-82743LOWAsh.Actions.Read.AsyncLimiter busy-spins a scheduler while awaiting slow async readsEPSS 0.2%CVE-2026-81869MEDIUMOpenTelemetry-Go: UTF-8 replacement rune bypasses attribute length truncationEPSS 0.2%CVE-2025-59529MEDIUMsimple protocol server ignores accepts unlimited connections and logs failures without limitEPSS 0.2%CVE-2026-48155MEDIUMpypdf: Possible large memory usage for large offsets for layout mode textEPSS 0.2%CVE-2026-27576MEDIUMOpenClaw: ACP prompt-size checks missing in local stdio bridge could reduce responsiveness with very large inputsEPSS 0.2%CVE-2026-43653MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS EPSS 0.2%CVE-2025-40802LOWA vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions). The affected device may be susceptible to resourceEPSS 0.2%CVE-2019-25724HIGHDräger Infinity M300 VG2.x Network-Based Denial of ServiceEPSS 0.2%CVE-2026-71642MEDIUMAn issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denEPSS 0.2%CVE-2023-25179MEDIUMUncontrolled resource consumption in the Intel(R) Unite(R) android application before Release 17 may allow an authenticated user to potentiaEPSS 0.2%CVE-2026-49461MEDIUMpypdf: Possible large memory usage for form XObjects during text extractionEPSS 0.2%CVE-2022-46645MEDIUMUncontrolled resource consumption in the Intel(R) Smart Campus Android application before version 9.9 may allow an authenticated user to potEPSS 0.2%CVE-2022-41801MEDIUMUncontrolled resource consumption in the Intel(R) Connect M Android application before version 1.82 may allow an authenticated user to potenEPSS 0.2%CVE-2026-60747MEDIUMVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affeEPSS 0.2%CVE-2024-57673MEDIUMAn issue in floodlight v1.2 allows a local attacker to cause a denial of service via the Topology Manager module and Linkdiscovery moduleEPSS 0.2%