Falhas do tipo CWE-400

2.952 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2025-53645HIGHZimbra Collaboration (ZCS) before 9.0.0 Patch 46, 10.0.x before 10.0.15, and 10.1.x before 10.1.9 is vulnerable to a denial of service condiEPSS 1.4%CVE-2023-0662HIGHDoS vulnerability when parsing multipart request bodyEPSS 1.4%CVE-2021-29506MEDIUMNavigate endpoint is vulnerable to regex injection that may lead to Denial of Service.EPSS 1.4%CVE-2020-3559MEDIUMCisco Aironet Access Point Authentication Flood Denial of Service VulnerabilityEPSS 1.4%CVE-2019-10923HIGHAn attacker with network access to an affected product may cause a denial of service condition by breaking the real-time synchronization (IREPSS 1.4%CVE-2025-49716HIGHWindows Netlogon Denial of Service VulnerabilityEPSS 1.4%CVE-2016-10539negotiator is an HTTP content negotiator for Node.js and is used by many modules and frameworks including Express and Koa. The header for "AEPSS 1.4%CVE-2022-36064MEDIUMShescape Inefficient Regular Expression Complexity vulnerabilityEPSS 1.4%CVE-2024-40634HIGHArgo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook EndpointEPSS 1.4%CVE-2021-22116RabbitMQ all versions prior to 3.8.16 are prone to a denial of service vulnerability due to improper input validation in AMQP 1.0 client conEPSS 1.4%CVE-2022-38150MEDIUMIn Varnish Cache 7.0.0, 7.0.1, 7.0.2, and 7.1.0, it is possible to cause the Varnish Server to assert and automatically restart through forgEPSS 1.4%CVE-2022-21689HIGHDenial of Service in OnionshareEPSS 1.4%CVE-2023-50967HIGHlatchset jose through version 11 allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.EPSS 1.4%CVE-2021-43838MEDIUMRegular Expression Denial of Service (ReDoS) in jsx-slackEPSS 1.4%CVE-2021-20185It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that messaging did not impose a character limit when sending messages,EPSS 1.4%CVE-2020-27782A flaw was found in the Undertow AJP connector. Malicious requests and abrupt connection closes could be triggered by an attacker using querEPSS 1.4%CVE-2020-3571HIGHCisco Firepower 4110 ICMP Flood Denial of Service VulnerabilityEPSS 1.4%CVE-2023-25816MEDIUMnextcloud vulnerable to Uncontrolled Resource ConsumptionEPSS 1.4%CVE-2022-38371HIGHA vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (EPSS 1.4%CVE-2018-6347HIGHAn issue in the Proxygen handling of HTTP2 parsing of headers/trailers can lead to a denial-of-service attack. This affects Proxygen prior tEPSS 1.4%