Falhas do tipo CWE-400

2.979 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2017-0938Denial of Service attack in airMAX < 8.3.2 , airMAX < 6.0.7 and EdgeMAX < 1.9.7 allow attackers to use the Discovery Protocol in amplificatiEPSS 21.0%CVE-2025-67779HIGHIt was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attacEPSS 20.0%CVE-2024-31152MEDIUMThe LevelOne WBR-6012 router with firmware R0.40e6 is vulnerable to improper resource allocation within its web application, where a series EPSS 17.8%CVE-2019-14901HIGHA heap overflow flaw was found in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The vulnerabiliEPSS 16.9%CVE-2010-5107HIGHThe default configuration of OpenSSH through 6.1 enforces a fixed time limit between establishing a TCP connection and completing a login, wEPSS 16.5%CVE-2019-5737In Node.js including 6.x before 6.17.0, 8.x before 8.15.1, 10.x before 10.15.2, and 11.x before 11.10.1, an attacker can cause a Denial of SEPSS 16.2%CVE-2026-34650HIGHAdobe Commerce | Uncontrolled Resource Consumption (CWE-400)EPSS 15.9%CVE-2021-35559MEDIUMVulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported versions that are afEPSS 15.9%CVE-2023-22512HIGHThis High severity DoS (Denial of Service) vulnerability was introduced in version 5.6.0 of Confluence Data Center and Server. With a CVSS SEPSS 15.4%CVE-2022-24713HIGHRegular expression denial of service in Rust's regex crateEPSS 14.5%CVE-2026-34649HIGHAdobe Commerce | Uncontrolled Resource Consumption (CWE-400)EPSS 14.4%CVE-2023-38180HIGH.NET and Visual Studio Denial of Service VulnerabilityEPSS 14.0%KEVCVE-2024-8182HIGHFlowise Denial of ServiceEPSS 13.9%CVE-2021-21348MEDIUMXStream is vulnerable to an attack using Regular Expression for a Denial of Service (ReDos)EPSS 13.8%CVE-2022-3094HIGHAn UPDATE message flood may cause named to exhaust all available memoryEPSS 13.2%CVE-2022-20624HIGHCisco NX-OS Software Cisco Fabric Services Over IP Denial of Service VulnerabilityEPSS 12.4%CVE-2018-16844MEDIUMnginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive CPU usage. This issEPSS 12.4%CVE-2024-6036HIGHDenial of Service in gaizhenbiao/chuanhuchatgptEPSS 10.9%CVE-2018-12121Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Denial of Service with large HTTP headers: By using a combinationEPSS 10.2%CVE-2019-10952Rockwell Automation CompactLogix 5370 Uncontrolled Resource ConsumptionEPSS 10.0%