Falhas do tipo CWE-400

3.039 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2026-35901MEDIUMA handling issue in the RTSP service of the Mercury MIPC252W 1.0.5 Build 230306 Rel.79931n allows an authenticated attacker to trigger sessiEPSS 0.2%CVE-2026-55782LOWNanaZip: Unbounded memory allocation (DoS) in NanaZip WebAssembly parser via attacker-controlled section/name length fieldsEPSS 0.2%CVE-2023-6450MEDIUMAn incorrect permissions vulnerability was reported in the Lenovo App Store app that could allow an attacker to use system resources, resultEPSS 0.2%CVE-2025-60753MEDIUMAn issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c when processing craftedEPSS 0.2%CVE-2026-14683MEDIUMHdrHistogram AbstractHistogram.java memory allocationEPSS 0.2%CVE-2026-52857MEDIUMWings: Maliciously or erroneously created parsed config files can cause wings process to OOMEPSS 0.2%CVE-2025-9341MEDIUMGarbage collection can delay for AES CBC Native support, resulting in heap exhaustionEPSS 0.2%CVE-2026-14684MEDIUMHdrHistogram AbstractHistogram.java memory allocationEPSS 0.2%CVE-2026-71616MEDIUMAn issue in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an attacker to cause a denial of service via the function gf_route_media_coEPSS 0.2%CVE-2026-64724MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOEPSS 0.2%CVE-2026-4174MEDIUMRadare2 Mach-O File mach0.c walk_exports_trie resource consumptionEPSS 0.2%CVE-2026-55781LOWNanaZip: Unbounded memory allocation (DoS) in NanaZip UFS parser via unvalidated fs_bsize/fs_fsize superblock fieldsEPSS 0.2%CVE-2026-4539MEDIUMpygments archetype.py AdlLexer redosEPSS 0.2%CVE-2026-55373MEDIUMOpenEXR: OpenEXRUtil SampleCountChannel endEdit() can loop forever on UINT_MAX sample countsEPSS 0.2%CVE-2026-46914HIGHVulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is affected is 11.4. EasEPSS 0.2%CVE-2025-12194MEDIUMUncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java FIPS bc-fips on All (API modules)EPSS 0.2%CVE-2025-69646MEDIUMBinutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logEPSS 0.2%CVE-2023-31889MEDIUMAn issue discovered in httpd in ASUS RT-AC51U with firmware version up to and including 3.0.0.4.380.8591 allows local attackers to cause a dEPSS 0.2%CVE-2026-47044MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.2%CVE-2026-87279MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.2%