Falhas do tipo CWE-400

3.039 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2026-60747MEDIUMVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affeEPSS 0.2%CVE-2022-43880MEDIUMIBM QRadar WinCollect AgentEPSS 0.2%CVE-2026-58045MEDIUMA flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigger a reachable assertion in the synchronous `node:zlib` APIs, causing tEPSS 0.2%CVE-2025-69645MEDIUMBinutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logicEPSS 0.2%CVE-2022-30691MEDIUMUncontrolled resource consumption in the Intel(R) Support Android application before version 22.02.28 may allow an authenticated user to potEPSS 0.2%CVE-2023-7258MEDIUMDenial-of-Service in GvisorEPSS 0.2%CVE-2026-87285MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.2%CVE-2026-87283MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.2%CVE-2026-47041MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.2%CVE-2025-66676MEDIUMAn issue in IObit Unlocker v1.3.0.11 allows attackers to cause a Denial of Service (DoS) via a crafted request.EPSS 0.2%CVE-2026-71128MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.2%CVE-2026-87282MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.2%CVE-2025-23246MEDIUMNVIDIA vGPU software for Windows and Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it allows a guest to conEPSS 0.2%CVE-2025-41227MEDIUMDenial-of-Service VulnerabilityEPSS 0.2%CVE-2023-37195MEDIUMA vulnerability has been identified in SIMATIC CP 1604 (All versions), SIMATIC CP 1616 (All versions), SIMATIC CP 1623 (All versions), SIMATEPSS 0.2%CVE-2026-53495MEDIUMcontainerd CRI ExecSync Goroutine Leak Leading to Node-Level Denial of ServiceEPSS 0.2%CVE-2026-28932MEDIUMA logic issue existed resulting in memory corruption. This was addressed with improved state management. This issue is fixed in macOS SequoiEPSS 0.2%CVE-2022-4816MEDIUMA denial-of-service vulnerability has been identified in Lenovo Safecenter that could allow a local user to crash the application.EPSS 0.2%CVE-2026-43768MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. AEPSS 0.2%CVE-2022-20482MEDIUMIn createNotificationChannel of NotificationManager.java, there is a possible way to make the device unusable and require factory reset due EPSS 0.2%