Falhas do tipo CWE-400

3.041 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2025-27576LOWUncontrolled resource consumption for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platform may allow EPSS 0.1%CVE-2025-55631MEDIUMReolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 was discovered to manage users' sessions system EPSS 0.1%CVE-2026-43806MEDIUMA denial of service issue was addressed by removing the vulnerable code. This issue is fixed in macOS Tahoe 26.6. A local attacker may be abEPSS 0.1%CVE-2026-38763MEDIUMAn issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to cause a denial of service via the function sub_13828EPSS 0.1%CVE-2024-57672MEDIUMAn issue in floodlight v1.2 allows a local attacker to cause a denial of service via the Topology Manager module, Topologylnstance module, REPSS 0.1%CVE-2026-21942MEDIUMVulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems). Supported versions that are affected are 10 and 11EPSS 0.1%CVE-2025-26697MEDIUMUncontrolled resource consumption in the Linux kernel-mode driver for some Intel(R) 700 Series Ethernet before version 2.28.5 may allow an aEPSS 0.1%CVE-2025-26863MEDIUMUncontrolled resource consumption in the Linux kernel-mode driver for some Intel(R) 700 Series Ethernet before version 2.28.5 may allow an aEPSS 0.1%CVE-2025-60419MEDIUMAn issue was discovered in the NDIS Usermode IO driver (RtkIOAC60.sys, version 6.0.5600.16348) allowing local authenticated attackers to senEPSS 0.1%CVE-2023-20910MEDIUMIn add of WifiNetworkSuggestionsManager.java, there is a possible way to trigger permanent DoS due to resource exhaustion. This could lead tEPSS 0.1%CVE-2026-40951MEDIUMMemory corruption in Secure Access Windows clients prior to 14.50EPSS 0.1%CVE-2026-16952MEDIUMVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.1%CVE-2022-25326MEDIUMDenial of Service in fscryptEPSS 0.1%CVE-2025-61480HIGHAn issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial ofEPSS 0.1%CVE-2025-69644MEDIUMAn issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary witEPSS 0.1%CVE-2025-27249MEDIUMUncontrolled resource consumption for some Gaudi software before version 1.21.0 within Ring 3: User Applications may allow a denial of serviEPSS 0.1%CVE-2023-20922MEDIUMIn setMimeGroup of PackageManagerService.java, there is a possible crash loop due to resource exhaustion. This could lead to local denial ofEPSS 0.1%CVE-2023-20908MEDIUMIn several functions of SettingsState.java, there is a possible system crash loop due to resource exhaustion. This could lead to local deniaEPSS 0.1%CVE-2026-55595MEDIUMImageMagick: Infinite Loop in connected-components when providing invalid argumentsEPSS 0.1%CVE-2026-0064CRITICALIn multiple places, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service EPSS 0.1%