Falhas do tipo CWE-400

3.000 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2026-69152HIGHbrace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigationEPSS 0.7%CVE-2022-46399HIGHThe Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) is unresponsive with ConReqTimeoutZerEPSS 0.7%CVE-2022-33203HIGHBIG-IP APM and F5 SSL Orchestrator vulnerability CVE-2022-33203EPSS 0.7%CVE-2024-25398HIGHIn Srelay (the SOCKS proxy and Relay) v.0.4.8p3, a specially crafted network payload can trigger a denial of service condition and disrupt tEPSS 0.7%CVE-2022-35236HIGHHTTP2 profile vulnerability CVE-2022-35236EPSS 0.7%CVE-2019-0038MEDIUMSRX Series: Crafted packets destined to fxp0 management interface on SRX340/SRX345 devices can lead to DoSEPSS 0.7%CVE-2025-49763HIGHApache Traffic Server: Remote DoS via memory exhaustion in ESI PluginEPSS 0.7%CVE-2025-4215LOWgorhill uBlock Origin UI 1p-filters.js currentStateChanged redosEPSS 0.7%CVE-2026-58210HIGHNATS Server: MQTT partial CONNECT packets can exhaust pre-auth memoryEPSS 0.7%CVE-2026-6607MEDIUMlm-sys fastchat Worker API Endpoint api_generate resource consumptionEPSS 0.7%CVE-2020-26652—An issue was discovered in function nl80211_send_chandef in rtl8812au v5.6.4.2 allows attackers to cause a denial of service.EPSS 0.7%CVE-2026-66142HIGHApache Neethi: Uncontrolled recursion in policy processingEPSS 0.7%CVE-2026-59173HIGHApache Traffic Server: DoS vulnerability in HTTP/2 via stalled flow-control conditionsEPSS 0.7%CVE-2026-42402HIGHApache Neethi: Policy Normalization Unbounded Resource Allocation DoSEPSS 0.7%CVE-2026-66144HIGHApache Neethi: Remote PolicyReference fetch lacks resource boundsEPSS 0.7%CVE-2026-66299HIGHApache Tomcat: DoS via WebSocket chat exampleEPSS 0.7%CVE-2026-50645HIGHApache CXF: No restriction on attachment headers per messageEPSS 0.7%CVE-2026-68763HIGHApache Tomcat: DoS via allocation leak in HTTP/2 backlog tracking when a stream is resetEPSS 0.7%CVE-2026-24012HIGHApache IoTDB: Denial of Service via Resource Exhaustion in Aggregation QueryEPSS 0.7%CVE-2022-28229HIGHThe hash functionality in userver before 42059b6319661583b3080cab9b595d4f8ac48128 allows attackers to cause a denial of service via crafted EPSS 0.7%