Falhas do tipo CWE-400

3.000 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2023-36818MEDIUMDenial of service via User Custom Sidebar Section Unlimited Link Creation in discourseEPSS 0.7%CVE-2023-38498MEDIUMDiscourse vulnerable to DoS via defer queueEPSS 0.7%CVE-2026-73633HIGHApache Struts: Unbounded read of a JSON request bodyEPSS 0.7%CVE-2026-84553HIGHA resource exhaustion issue was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, mEPSS 0.7%CVE-2023-37463MEDIUMQuadratic complexity bugs may lead to a denial of serviceEPSS 0.7%CVE-2026-25771MEDIUMWazuh Vulnerable to Denial of Service via Synchronous I/O Blocking in Asynchronous Authentication MiddlewareEPSS 0.7%CVE-2020-15101LOWNested directory structure can lead to Uncontrolled Resource Consumption in freewvsEPSS 0.7%CVE-2024-23744HIGHAn issue was discovered in Mbed TLS 3.5.1. There is persistent handshake denial if a client sends a TLS 1.3 ClientHello without extensions.EPSS 0.7%CVE-2021-43933MEDIUMICSA-22-109-03 FANUC ROBOGUIDE Simulation PlatformEPSS 0.7%CVE-2023-29153MEDIUMUncontrolled resource consumption for some Intel(R) SPS firmware before version SPS_E5_06.01.04.002.0 may allow a privileged user to potentiEPSS 0.7%CVE-2026-4410MEDIUMIBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a denial of serviceEPSS 0.7%CVE-2025-59043HIGHOpenBao vulnerable to denial of service via malicious JSON request processingEPSS 0.7%CVE-2020-1702—A malicious container image can consume an unbounded amount of memory when being pulled to a container runtime host, such as Red Hat EnterprEPSS 0.7%CVE-2023-28440LOWDenial of service via admin theme import route in DiscourseEPSS 0.7%CVE-2026-47707MEDIUMStrawberry GraphQL's Bypass of MaxAliasesLimiter via Fragment Spreads leading to GraphQL Alias AmplificationEPSS 0.7%CVE-2024-25269HIGHlibheif <= 1.17.6 contains a memory leak in the function JpegEncoder::Encode. This flaw allows an attacker to cause a denial of service attaEPSS 0.7%CVE-2026-50750HIGHApache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: Pre-authentication OpenWire DoS following fix for CVE-2026-49270EPSS 0.7%CVE-2025-29907HIGHjsPDF Bypass Regular Expression Denial of Service (ReDoS)EPSS 0.7%CVE-2023-37480LOWFides Webserver Vulnerable to Zip Bomb File UploadsEPSS 0.7%CVE-2023-43810HIGHopentelemetry-instrumentation Denial of Service vulnerability due to unbound cardinality metricsEPSS 0.7%