Falhas do tipo CWE-400

2.995 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2025-24260CRITICALThe issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5.EPSS 0.9%CVE-2022-44608HIGHUncontrolled resource consumption vulnerability in Cybozu Remote Service 4.0.0 to 4.0.3 allows a remote authenticated attacker to consume huEPSS 0.9%CVE-2024-21171MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.37 aEPSS 0.9%CVE-2022-27182MEDIUMOn F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, and 14.1.x versions prior to 14.1.4.6, when BIG-IP packetEPSS 0.9%CVE-2024-20716MEDIUMForce high-usage of resources by generating unlimited coupons: Adobe CommerceEPSS 0.9%CVE-2024-21231LOWVulnerability in the MySQL Server product of Oracle MySQL (component: Client programs). Supported versions that are affected are 8.0.39 andEPSS 0.9%CVE-2022-2529HIGHMultiple DoS Attack Vectors in sflow packet handlingEPSS 0.9%CVE-2023-51775MEDIUMThe jose4j component before 0.9.4 for Java allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count)EPSS 0.9%CVE-2020-1750A flaw was found in the machine-config-operator that causes an OpenShift node to become unresponsive when a container consumes a large amounEPSS 0.9%CVE-2026-54399HIGHApache HttpComponents Core: Unbounded HTTP Header/Line Length in Default ConfigurationEPSS 0.9%CVE-2023-45621HIGHUnauthenticated Denial-of-Service (DoS) vulnerabilities exist in the CLI service accessed via the PAPI protocol. Successful exploitation of EPSS 0.9%CVE-2023-45622HIGHUnauthenticated Denial-of-Service (DoS) vulnerabilities exist in the BLE daemon service accessed via the PAPI protocol. Successful exploitatEPSS 0.9%CVE-2026-54428HIGHApache HttpComponents Core: HPackDecoder Unlimited Header List Size Before SETTINGS ACKEPSS 0.9%CVE-2022-30792HIGHCODESYS: CmpChannelServer, CmpChannelServerEmbedded allow unauthenticated attackers to block all their available communication channelsEPSS 0.9%CVE-2022-30791HIGHCODESYS V3: CmpBlkDrvTcp allows unauthenticated attackers to block all its available TCP connectionsEPSS 0.9%CVE-2025-4727MEDIUMMeteor livedata_server.js Object.assign redosEPSS 0.9%CVE-2023-48713MEDIUMKnative Serving vulnerable to attacker-controlled pod causing denial of service of autoscalerEPSS 0.9%CVE-2023-20051MEDIUMCisco Packet Data Network Gateway IPsec ICMP Denial of Service VulnerabilityEPSS 0.9%CVE-2023-35921HIGHA vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3.4), SIMATIC MV540 S (All versions < V3.3.4), SIMATIC MV550 H (AlEPSS 0.9%CVE-2023-35920HIGHA vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3.4), SIMATIC MV540 S (All versions < V3.3.4), SIMATIC MV550 H (AlEPSS 0.9%