Falhas do tipo CWE-400

3.000 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2022-33168HIGHIBM Security Directory Suite VA denial of serviceEPSS 0.8%CVE-2024-8418HIGHContainers/aardvark-dns: tcp query handling flaw in aardvark-dns leading to denial of serviceEPSS 0.8%CVE-2026-42403HIGHApache Neethi: Circular Policy Reference Infinite LoopEPSS 0.8%CVE-2024-7771MEDIUMDenial of Service in mintplex-labs/anything-llmEPSS 0.8%CVE-2023-6193MEDIUMUnbounded queuing of path validation messages in cloudflare-quicheEPSS 0.8%CVE-2026-57576MEDIUMplone.app.dexterity and plone.app.contenttypes have a Denial of Service due to excessive title or description lengthEPSS 0.8%CVE-2024-32984HIGHYamux Memory Exhaustion Vulnerability via Active::pending_frames property EPSS 0.8%CVE-2022-23524MEDIUMHelm vulnerable to Denial of service through string value parsingEPSS 0.8%CVE-2022-35915MEDIUMUnbounded gas consumption in @openzeppelin/contractsEPSS 0.8%CVE-2024-21177MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.37 aEPSS 0.8%CVE-2024-21232LOWVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services). Supported versions that are affected arEPSS 0.8%CVE-2023-46361—Artifex Software jbig2dec v0.20 was discovered to contain a SEGV vulnerability via jbig2_error at /jbig2dec/jbig2.c.EPSS 0.8%CVE-2023-49550HIGHAn issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs+0x4ec508 component.EPSS 0.8%CVE-2023-27567—In OpenBSD 7.2, a TCP packet with destination port 0 that matches a pf divert-to rule can crash the kernel.EPSS 0.8%CVE-2023-3825HIGH PTC’s KEPServerEX Versions 6.0 to 6.14.263 are vulnerable to being made to read a recursively defined object that leads to uncontrolled resEPSS 0.8%CVE-2023-39748—An issue in the component /userRpm/NetworkCfgRpm of TP-Link TL-WR1041N V2 allows attackers to cause a Denial of Service (DoS) via a crafted EPSS 0.8%CVE-2026-55407MEDIUMBuffa: Memory Exhaustion Denial of Service in decode_unknown_field via Unbounded AllocationEPSS 0.8%CVE-2023-45874MEDIUMAn issue was discovered in Couchbase Server through 7.2.2. A data reader may cause a denial of service (outage of reader threads).EPSS 0.8%CVE-2024-21163MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.37 aEPSS 0.8%CVE-2026-48043MEDIUMnetty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory ExhaustionEPSS 0.8%