Falhas do tipo CWE-400

2.999 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2021-38465HIGHAUVESY VersiondogEPSS 0.8%CVE-2022-1468MEDIUMOn all versions of 17.0.x, 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x on F5 BIG-IP, an authenticated iControl REST user with at leasEPSS 0.8%CVE-2022-35776MEDIUMAzure Site Recovery Denial of Service VulnerabilityEPSS 0.8%CVE-2024-21062MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.36 aEPSS 0.8%CVE-2021-23852MEDIUMDenial of Service (DoS) due to invalid web parameterEPSS 0.8%CVE-2022-37884HIGHA vulnerability exists in the ClearPass Policy Manager Guest User Interface that can allow an unauthenticated attacker to send specific operEPSS 0.8%CVE-2026-68763HIGHApache Tomcat: DoS via allocation leak in HTTP/2 backlog tracking when a stream is resetEPSS 0.8%CVE-2022-20960HIGHA vulnerability in Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated remote attacker to cause aEPSS 0.8%CVE-2024-41818HIGHReDOS at currency parsing fast-xml-parserEPSS 0.8%CVE-2022-23580MEDIUMAbort caused by allocating a vector that is too large in TensorflowEPSS 0.8%CVE-2025-7070MEDIUMIROAD Dashcam Q9 MFA Pairing Request allocation of resourcesEPSS 0.8%CVE-2023-50730HIGHGrackle has StackOverflowError in GraphQL query processingEPSS 0.8%CVE-2023-4486HIGHUncontrolled Resource Consumption in Metasys and Facility ExplorerEPSS 0.8%CVE-2024-20344MEDIUMA vulnerability in system resource management in Cisco UCS 6400 and 6500 Series Fabric Interconnects that are in Intersight Managed Mode (IMEPSS 0.8%CVE-2025-5024HIGHGnome-remote-desktop: uncontrolled resource consumption due to malformed rdp pdusEPSS 0.8%CVE-2025-53012MEDIUMMaterialX's Lack of Import Depth Limit Leads to DoS (Denial-Of-Service) Via Stack ExhaustionEPSS 0.8%CVE-2024-21173MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.37 and prior anEPSS 0.8%CVE-2024-21130MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.37 aEPSS 0.8%CVE-2024-9409HIGHCWE-400: An Uncontrolled Resource Consumption vulnerability exists that could cause the device to become unresponsive resulting in communicaEPSS 0.8%CVE-2022-43572HIGHIndexing blockage via malformed data sent through S2S or HEC protocols in Splunk EnterpriseEPSS 0.8%