Falhas do tipo CWE-400

3.041 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2026-22003MEDIUMVulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions tEPSS 0.1%CVE-2026-18822MEDIUMVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.1%CVE-2026-0049MEDIUMIn onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhaustion. This could lead EPSS 0.1%CVE-2026-19653MEDIUMVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.1%CVE-2024-49740MEDIUMIn multiple locations, there is a possible crash loop due to resource exhaustion. This could lead to local denial of service with no additioEPSS 0.1%CVE-2025-48590MEDIUMIn verifyAndGetBypass of AppOpsService.java, there is a possible method for a malicious app to prevent dialing emergency services under limiEPSS 0.1%CVE-2024-0026MEDIUMIn multiple functions of SnoozeHelper.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to EPSS 0.1%CVE-2025-48584MEDIUMIn multiple functions of NotificationManagerService.java, there is a possible way to bypass the per-package channel limits causing resource EPSS 0.1%CVE-2022-38674MEDIUMIn wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.EPSS 0.1%CVE-2025-26423MEDIUMIn validateIpConfiguration of WifiConfigurationUtil.java, there is a possible way to trigger a permanent DoS due to a missing bounds check. EPSS 0.1%CVE-2023-21090MEDIUMIn parseUsesPermission of ParsingPackageUtils.java, there is a possible boot loop due to resource exhaustion. This could lead to local deniaEPSS 0.1%CVE-2018-9447MEDIUMIn onCreate of EmergencyCallbackModeExitDialog.java, there is a possible way to crash the emergency callback mode due to a missing null checEPSS 0.1%CVE-2022-47370MEDIUMIn wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.EPSS 0.1%CVE-2023-21033MEDIUMIn addNetwork of WifiManager.java, there is a possible way to trigger a persistent DoS due to resource exhaustion. This could lead to local EPSS 0.1%CVE-2022-38677MEDIUMIn cell service, there is a missing permission check. This could lead to local denial of service in cell service with no additional executioEPSS 0.1%CVE-2026-28596MEDIUMIn parseInterventionFromXml of GameManagerService.java, there is a possible permanent denial of service due to resource exhaustion. This couEPSS 0.1%CVE-2026-28617MEDIUMIn add of WifiNetworkSuggestionsManager.java, there is a possible persistent DOS due to resource exhaustion. This could lead to local denialEPSS 0.1%CVE-2025-48603MEDIUMIn InputMethodInfo of InputMethodInfo.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to lEPSS 0.1%CVE-2025-48576MEDIUMIn updateNotificationChannelGroupFromPrivilegedListener of NotificationManagerService.java, there is a possible permanent denial of service EPSS 0.1%CVE-2025-26463MEDIUMIn allowPackageAccess of multiple files, resource exhaustion is possible when repeatedly adding allowed packages. This could lead to a localEPSS 0.1%