Falhas do tipo CWE-400

2.967 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2016-10539negotiator is an HTTP content negotiator for Node.js and is used by many modules and frameworks including Express and Koa. The header for "AEPSS 1.4%CVE-2020-25630A vulnerability was found in Moodle where the decompressed size of zip files was not checked against available user quota before unzipping tEPSS 1.4%CVE-2019-19301HIGHA vulnerability has been identified in SCALANCE X200-4P IRT, SCALANCE X201-3P IRT, SCALANCE X201-3P IRT PRO, SCALANCE X202-2IRT, SCALANCE X2EPSS 1.4%CVE-2019-10942A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.5), SCALANCE X-200IRT sEPSS 1.4%CVE-2021-41119MEDIUMDoS vulnerabiliity in wire-server json parserEPSS 1.4%CVE-2022-22543SAP NetWeaver Application Server for ABAP (Kernel) and ABAP Platform (Kernel) - versions KERNEL 7.22, 8.04, 7.49, 7.53, 7.77, 7.81, 7.85, 7.EPSS 1.4%CVE-2025-29954MEDIUMWindows Lightweight Directory Access Protocol (LDAP) Denial of Service VulnerabilityEPSS 1.4%CVE-2018-6346HIGHA potential denial-of-service issue in the Proxygen handling of invalid HTTP2 priority settings (specifically a circular dependency). This aEPSS 1.4%CVE-2018-6347HIGHAn issue in the Proxygen handling of HTTP2 parsing of headers/trailers can lead to a denial-of-service attack. This affects Proxygen prior tEPSS 1.4%CVE-2020-14384A flaw was found in JBossWeb in versions before 7.5.31.Final-redhat-3. The fix for CVE-2020-13935 was incomplete in JBossWeb, leaving it vulEPSS 1.4%CVE-2023-39321Panic when processing post-handshake message on QUIC connections in crypto/tlsEPSS 1.4%CVE-2018-16486A prototype pollution vulnerability was found in defaults-deep <=0.2.4 that would allow a malicious user to inject properties onto Object.prEPSS 1.4%CVE-2022-3204HIGHNRDelegation AttackEPSS 1.3%CVE-2020-11645MEDIUMGateManager Denial of Service VulnerabilityEPSS 1.3%CVE-2017-16021uri-js is a module that tries to fully implement RFC 3986. One of these features is validating whether or not a supplied URL is valid or notEPSS 1.3%CVE-2018-3767`memjs` versions <= 1.1.0 allocates and stores buffers on typed input, resulting in DoS and uninitialized memory usage.EPSS 1.3%CVE-2021-32722MEDIUMUncontrolled Resource Consumption in GlobalNewFilesEPSS 1.3%CVE-2021-39171MEDIUMUnlimited transforms allowed for signed nodesEPSS 1.3%CVE-2019-0059HIGHJunos OS: The routing protocol process (rpd) may crash and generate core files upon receipt of specific valid BGP states from a peered host.EPSS 1.3%CVE-2023-34458HIGHmx-chain-go's relayed transactions always increment nonceEPSS 1.3%