Falhas do tipo CWE-400

3.000 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2025-53114HIGHCometD has acknowledgement extension out of memoryEPSS 0.7%CVE-2026-37459HIGHAn integer underflow in FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a craftEPSS 0.7%CVE-2026-49485HIGHHAPI FHIR: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP EndpointEPSS 0.7%CVE-2022-31079MEDIUMKubeEdge Cloud Stream and Edge Stream DoS from large stream messageEPSS 0.7%CVE-2025-0704MEDIUMJoeyBling bootplus QrCodeController.java qrCode resource consumptionEPSS 0.7%CVE-2022-31078MEDIUMKubeEdge CloudCore Router memory exhaustionEPSS 0.7%CVE-2022-46352HIGHA vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALAEPSS 0.7%CVE-2024-42943HIGHTenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the PPPOEPassword parameter in the fromAdvSetWan function. This EPSS 0.7%CVE-2024-34483HIGHOFPGroupDescStats in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via OFPBucket.len=0.EPSS 0.7%CVE-2024-24988MEDIUMExcessive resource consumption when sending long emoji names in user custom statusEPSS 0.7%CVE-2023-26044MEDIUMReactPHP's HTTP server continues parsing unused multipart parts after reaching limitsEPSS 0.7%CVE-2022-4767HIGHDenial of Service in usememos/memosEPSS 0.7%CVE-2023-23616LOWDiscourse membership requests lack character limitEPSS 0.7%CVE-2023-2831MEDIUMDenial of Service while unescaping a Markdown stringEPSS 0.7%CVE-2023-27484MEDIUMUnchecked fieldpath index in Composition's patches can lead to arbitrary memory allocation in crossplaneEPSS 0.7%CVE-2023-50020HIGHAn issue was discovered in open5gs v2.6.6. SIGPIPE can be used to crash AMF.EPSS 0.7%CVE-2023-23625MEDIUMDenial of service in HAMT Decoding in go-unixfs EPSS 0.7%CVE-2021-26945—An integer overflow leading to a heap-buffer overflow was found in OpenEXR in versions before 3.0.1. An attacker could use this flaw to crasEPSS 0.7%CVE-2019-5043MEDIUMAn exploitable denial-of-service vulnerability exists in the Weave daemon of the Nest Cam IQ Indoor, version 4620002. A set of TCP connectioEPSS 0.7%CVE-2026-59902HIGHNetty: Memory Exhaustion in SctpMessageCompletionHandlerEPSS 0.7%