Falhas do tipo CWE-400

2.987 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2023-21728HIGHWindows Netlogon Denial of Service VulnerabilityEPSS 2.0%CVE-2025-46392MEDIUMApache Commons Configuration: Uncontrolled Resource Consumption when loading untrusted configurations in 1.xEPSS 2.0%CVE-2020-3373HIGHCisco Adaptive Security Appliance Software and Firepower Threat Defense Software IP Fragment Memory Leak VulnerabilityEPSS 2.0%CVE-2025-26680HIGHWindows Standards-Based Storage Management Service Denial of Service VulnerabilityEPSS 2.0%CVE-2019-12658HIGHCisco IOS XE Software Filesystem Exhaustion Denial of Service VulnerabilityEPSS 2.0%CVE-2018-15388HIGHCisco Adaptive Security Appliance Software and Firepower Threat Defense Software WebVPN Denial of Service VulnerabilityEPSS 2.0%CVE-2019-12698MEDIUMCisco Adaptive Security Appliance Software and Firepower Threat Defense Software WebVPN CPU Denial of Service VulnerabilityEPSS 2.0%CVE-2020-3254HIGHCisco Adaptive Security Appliance Software and Firepower Threat Defense Software Media Gateway Control Protocol Denial of Service VulnerabilitiesEPSS 2.0%CVE-2025-21330HIGHWindows Remote Desktop Services Denial of Service VulnerabilityEPSS 2.0%CVE-2023-37379Apache Airflow: Exposure of sensitive connection information, DOS and SSRF on "test connection" featureEPSS 2.0%CVE-2020-36320HIGHRegular expression Denial of Service (ReDoS) in EmailValidator class in Vaadin 7EPSS 2.0%CVE-2024-54677MEDIUMApache Tomcat: DoS in examples web applicationEPSS 2.0%CVE-2021-21296LOWDenial-of-service in FleetEPSS 1.9%CVE-2025-21389HIGHWindows Universal Plug and Play (UPnP) Device Host Denial of Service VulnerabilityEPSS 1.9%CVE-2023-28217HIGHWindows Network Address Translation (NAT) Denial of Service VulnerabilityEPSS 1.9%CVE-2019-5472An authorization issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 that prevented owners and maintainer to delete epEPSS 1.9%CVE-2024-2757HIGHPHP mb_encode_mimeheader runs endlessly for some inputsEPSS 1.9%CVE-2017-16118The forwarded module is used by the Express.js framework to handle the X-Forwarded-For header. It is vulnerable to a regular expression deniEPSS 1.9%CVE-2020-3196HIGHCisco Adaptive Security Appliance Software and Firepower Threat Defense Software SSL/TLS Denial of Service VulnerabilityEPSS 1.9%CVE-2020-3195HIGHCisco Adaptive Security Appliance Software and Firepower Threat Defense Software OSPF Packets Processing Memory Leak VulnerabilityEPSS 1.9%