Falhas do tipo CWE-400

3.041 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2026-87279MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.2%CVE-2026-47044MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.2%CVE-2026-34281MEDIUMVulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11.4. Easily EPSS 0.2%CVE-2025-70347MEDIUMAn issue in mquickjs before commit 74b7e (2026-01-15) allows a local attacker to cause a denial of service via a crafted file to the get_mblEPSS 0.2%CVE-2026-47022LOWVulnerability in the GoldenGate Stream Analytics product of Oracle GoldenGate (component: Security). The supported version that is affecteEPSS 0.1%CVE-2024-54192MEDIUMAn issue inTcpreplay v4.5.1 allows a local attacker to cause a denial of service via a crafted file to the tcpedit_dlt_getplugin function atEPSS 0.1%CVE-2025-53068MEDIUMVulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exEPSS 0.1%CVE-2026-6844MEDIUMBinutils: binutils: denial of service vulnerabilities in readelf via crafted elf filesEPSS 0.1%CVE-2025-9092LOWHybrid Module Deployment in Multi-JVM Environments Leading to Resource ExhaustionEPSS 0.1%CVE-2025-66861LOWAn issue was discovered in function d_unqualified_name in file cp-demangle.c in BinUtils 2.26 allowing attackers to cause a denial of servicEPSS 0.1%CVE-2026-93587MEDIUMImageMagick before 7.1.2-31 Policy Bypass via PCD decoderEPSS 0.1%CVE-2025-52636LOWHCL AION is affected by a improper handling of uploads files SizeEPSS 0.1%CVE-2022-38687MEDIUMIn messaging service, there is a missing permission check. This could lead to local denial of service in messaging service with no additionaEPSS 0.1%CVE-2025-37139MEDIUMVulnerability in AOS firmware allows for Authenticated Local malicious actor to Permanently Disable BootEPSS 0.1%CVE-2026-20602MEDIUMThe issue was addressed with improved handling of caches. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3EPSS 0.1%CVE-2026-10695MEDIUMIBM® Db2® is vulnerable to a denial of service when running non fenced federated queriesEPSS 0.1%CVE-2026-62465MEDIUMVulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affeEPSS 0.1%CVE-2025-22242MEDIUMCVE-2025-22242 salt advisoryEPSS 0.1%CVE-2026-81880MEDIUMradare2: Uncontrolled resource consumption in radare2 PEF loaderEPSS 0.1%CVE-2025-6075LOWQuadratic complexity in os.path.expandvars() with user-controlled templateEPSS 0.1%