Falhas do tipo CWE-400

2.986 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2025-21207HIGHWindows Connected Devices Platform Service (Cdpsvc) Denial of Service VulnerabilityEPSS 2.1%CVE-2025-38501HIGHksmbd: limit repeated connections from clients with the same IPEPSS 2.1%CVE-2024-28176MEDIUMjose vulnerable to resource exhaustion via specifically crafted JWE with compressed plaintextEPSS 2.1%CVE-2015-9242Certain input strings when passed to new Date() or Date.parse() in ecstatic node module before 1.4.0 will cause v8 to raise an exception. ThEPSS 2.1%CVE-2021-21267HIGHRegular Expression Denial-of-Service in npm schema-inspectorEPSS 2.1%CVE-2025-27485HIGHWindows Standards-Based Storage Management Service Denial of Service VulnerabilityEPSS 2.1%CVE-2025-27486HIGHWindows Standards-Based Storage Management Service Denial of Service VulnerabilityEPSS 2.1%CVE-2025-21174HIGHWindows Standards-Based Storage Management Service Denial of Service VulnerabilityEPSS 2.1%CVE-2017-14028A Resource Exhaustion issue was discovered in Moxa NPort 5110 Version 2.2, NPort 5110 Version 2.4, NPort 5110 Version 2.6, NPort 5110 VersioEPSS 2.1%CVE-2019-7620Logstash versions before 7.4.1 and 6.8.4 contain a denial of service flaw in the Logstash Beats input plugin. An unauthenticated user who isEPSS 2.1%CVE-2021-21375MEDIUMCrash in receiving updated SDP answer after initial SDP negotiation failedEPSS 2.1%CVE-2022-1797MEDIUMRockwell Automation Logix Controllers Uncontrolled Resource ConsumptionEPSS 2.1%CVE-2022-32790HIGHThis issue was addressed with improved checks. This issue is fixed in tvOS 15.5, watchOS 8.6, iOS 15.5 and iPadOS 15.5, macOS Monterey 12.4,EPSS 2.1%CVE-2019-10936HIGHAffected devices improperly handle large amounts of specially crafted UDP packets. This could allow an unauthenticated remote attacker toEPSS 2.1%CVE-2024-35176MEDIUMREXML contains a denial of service vulnerabilityEPSS 2.1%CVE-2018-16470There is a possible DoS vulnerability in the multipart parser in Rack before 2.0.6. Specially crafted requests can cause the multipart parseEPSS 2.0%CVE-2018-0309A vulnerability in the implementation of a specific CLI command and the associated Simple Network Management Protocol (SNMP) MIB for Cisco NEPSS 2.0%CVE-2023-5157HIGHMariadb: node crashes with transport endpoint is not connected mysqld got signal 6EPSS 2.0%CVE-2018-3739https-proxy-agent before 2.1.1 passes auth option to the Buffer constructor without proper sanitization, resulting in DoS and uninitialized EPSS 2.0%CVE-2025-53506HIGHApache Tomcat: DoS via excessive h2 streams at connection startEPSS 2.0%