Falhas do tipo CWE-400

2.995 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2017-2681HIGHSpecially crafted PROFINET DCP packets sent on a local Ethernet segment (Layer 2) to an affected product could cause a denial of service conEPSS 0.9%CVE-2022-1982MEDIUMA crafted SVG attachment can crash a Mattermost serverEPSS 0.9%CVE-2022-41952MEDIUMUncontrolled Resource Consumption in Matrix Synapse EPSS 0.9%CVE-2022-3639MEDIUMA potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 10.8 before 15.1.6, all versions starting from 15.2EPSS 0.9%CVE-2023-34872MEDIUMA vulnerability in Outline.cc for Poppler prior to 23.06.0 allows a remote attacker to cause a Denial of Service (DoS) (crash) via a craftedEPSS 0.9%CVE-2022-23024On BIG-IP AFM version 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.2, and all versions of 13.1.x, when the IPsec applicaEPSS 0.9%CVE-2023-2990Fortra Globalscape Administration Server Denial of ServiceEPSS 0.9%CVE-2026-75632HIGHCAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)EPSS 0.9%CVE-2025-24264CRITICALThe issue was addressed with improved memory handling. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS SeEPSS 0.9%CVE-2022-29480MEDIUMOn F5 BIG-IP 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, when multiple route domains are configured, undisclosedEPSS 0.9%CVE-2023-40180HIGHDenial of service vulnerability in silverstripe-graphql via recursive queriesEPSS 0.9%CVE-2022-27181MEDIUMOn F5 BIG-IP APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prEPSS 0.9%CVE-2024-34506HIGHAn issue was discovered in includes/specials/SpecialMovePage.php in MediaWiki before 1.39.7, 1.40.x before 1.40.3, and 1.41.x before 1.41.1.EPSS 0.9%CVE-2021-37865MEDIUMServer-side Denial of Service while processing a specifically crafted GIF fileEPSS 0.9%CVE-2026-39304HIGHApache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Incorrect handling of TLSv1.3 KeyUpdate can be exploited to cause DoS via OOMEPSS 0.9%CVE-2024-21203MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: FTS). Supported versions that are affected are 8.0.39 and priEPSS 0.9%CVE-2022-23023On BIG-IP version 16.1.x before 16.1.2.1, 15.1.x before 15.1.5, 14.1.x before 14.1.4.5, and all versions of 13.1.x and 12.1.x, and BIG-IQ alEPSS 0.9%CVE-2021-22956An uncontrolled resource consumption vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 that could allow an attackerEPSS 0.9%CVE-2023-31006MEDIUMIBM Security Access Manager Container denial of serviceEPSS 0.9%CVE-2024-28717MEDIUMAn issue in OpenStack Storlets yoga-eom allows a remote attacker to execute arbitrary code via the gateway.py component.EPSS 0.9%