Falhas do tipo CWE-400

3.000 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2024-57519HIGHAn issue in Open5GS v.2.7.2 allows a remote attacker to cause a denial of service via the ogs_dbi_auth_info function in lib/dbi/subscriptionEPSS 0.7%CVE-2021-36395HIGHIn Moodle, the file repository's URL parsing required additional recursion handling to mitigate the risk of recursion denial of service.EPSS 0.7%CVE-2022-39294HIGH(DoS) Denial of Service from unchecked request length in conduit-hyperEPSS 0.7%CVE-2026-57819HIGHApache CXF: No default restriction on the amount of form parameters per messageEPSS 0.7%CVE-2026-33610MEDIUMPossible file descriptor exhaustion in forward-dnsupdateEPSS 0.7%CVE-2024-20351HIGHCisco Firepower Threat Defense Software Snort Firewall Denial of Service VulnerabilityEPSS 0.7%CVE-2021-3908MEDIUMInfinite certificate chain depth results in OctoRPKI running foreverEPSS 0.7%CVE-2026-58182HIGHApache Traffic Server: ts_lua plugin has initialization and resource-handling errorsEPSS 0.7%CVE-2022-42929MEDIUMIf a website called `window.print()` in a particular way, it could cause a denial of service of the browser, which may persist beyond browseEPSS 0.7%CVE-2026-73634HIGHApache Struts: Unbounded read of a Content Security Policy violation reportEPSS 0.7%CVE-2026-84304HIGHgRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame FragmentationEPSS 0.7%CVE-2024-11033MEDIUMDenial of Service (DoS) in binary-husky/gpt_academicEPSS 0.7%CVE-2023-49290MEDIUMMalicious parameters can cause a denial of service in lestrrat-go/jwxEPSS 0.7%CVE-2026-44891HIGHNetty: Denial of Service via Unbounded Headers in StompSubframeDecoderEPSS 0.7%CVE-2026-8769MEDIUMvercel ai provider-utils response-handler.ts createJsonErrorResponseHandler resource consumptionEPSS 0.7%CVE-2023-25774HIGHA denial-of-service vulnerability exists in the vpnserver ConnectionAccept() functionality of SoftEther VPN 5.02. A set of specially craftedEPSS 0.7%CVE-2026-34045HIGHPodman Desktop WebView Server ExposedEPSS 0.7%CVE-2026-59843MEDIUMLibssh: libssh: denial of service via zero advertised channel packet sizeEPSS 0.7%CVE-2026-92114MEDIUMa2ui-project a2ui Basic Catalog safe_regex.ts redosEPSS 0.7%CVE-2026-90584MEDIUMTooTallNate Java-WebSocket Fragmentation Draft_6455.java processFrameContinuousAndNonFin allocation of resourcesEPSS 0.7%