Falhas do tipo CWE-400

3.000 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2026-92114MEDIUMa2ui-project a2ui Basic Catalog safe_regex.ts redosEPSS 0.7%CVE-2023-41378HIGHCalico Typha hangs during unclean TLS handshakeEPSS 0.7%CVE-2025-0187HIGHDenial of Service (DoS) by Sending Large Filename at File Upload Endpoint in gradio-app/gradioEPSS 0.7%CVE-2023-40703MEDIUMDenial of Service via specially crafted block fields in Mattermost BoardsEPSS 0.7%CVE-2023-40586HIGHgo package github.com/corazawaf/coraza is vulnerable to denial of serviceEPSS 0.7%CVE-2023-48268MEDIUMDenial of Service via Board Import Zip BombEPSS 0.7%CVE-2025-21614HIGHgo-git clients vulnerable to DoS via maliciously crafted Git server repliesEPSS 0.7%CVE-2023-46131MEDIUMGrails® data binding causes JVM crash and/or DoS EPSS 0.7%CVE-2021-22906—Nextcloud End-to-End Encryption before 1.5.3, 1.6.3 and 1.7.1 suffers from a denial of service vulnerability due to permitting any authenticEPSS 0.7%CVE-2023-3782MEDIUMDoS of the OkHttp client when using a BrotliInterceptor and surfing to a malicious web server, or when an attacker can perform MitM to inject a Brotli zip-bomb into an HTTP responseEPSS 0.7%CVE-2022-35241MEDIUMNGINX Instance Manager vulnerability CVE-2022-35241EPSS 0.7%CVE-2025-70327CRITICALTOTOLINK X5000R v9.1.0cu_2415_B20250515 contains an argument injection vulnerability in the setDiagnosisCfg handler of the /usr/sbin/lighttpEPSS 0.7%CVE-2026-44241HIGHMicronaut Framework: Unbounded formattersCache in TimeConverterRegistrar Allows Memory Exhaustion via Accept-Language HeaderEPSS 0.7%CVE-2025-4533MEDIUMJeecgBoot Document Library Upload zip unzipFile resource consumptionEPSS 0.7%CVE-2023-28356HIGHA vulnerability has been identified where a maliciously crafted message containing a specific chain of characters can cause the chat to enteEPSS 0.7%CVE-2022-45044MEDIUMA vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V9.50), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 EPSS 0.7%CVE-2026-63448MEDIUMSuricata smb: some SMB flows can cause resource exhaustionEPSS 0.7%CVE-2024-24781HIGHHima: Uncontrolled Resource Consumption in multiple productsEPSS 0.7%CVE-2025-8262MEDIUMyarnpkg Yarn hosted-git-resolver.js explodeHostedGitFragment redosEPSS 0.7%CVE-2024-31992MEDIUMMealie contains a DoS vulnerability in recipe importerEPSS 0.7%