Falhas do tipo CWE-400

3.000 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2026-32588MEDIUMApache Cassandra: Authenticated DoS via ALTER ROLE Password HashingEPSS 0.7%CVE-2023-20176MEDIUMA vulnerability in the networking component of Cisco access point (AP) software could allow an unauthenticated, remote attacker to cause a tEPSS 0.7%CVE-2026-4671HIGHjusthtml before 1.18.0 Denial of Service via CSS SelectorEPSS 0.7%CVE-2023-36161—An issue was discovered in Qubo Smart Plug 10A version HSP02_01_01_14_SYSTEM-10A, allows attackers to cause a denial of service (DoS) via WiEPSS 0.7%CVE-2024-55605HIGHSuricata allows stack overflow in transformsEPSS 0.7%CVE-2024-6838MEDIUMUncontrolled Resource Consumption in mlflow/mlflowEPSS 0.7%CVE-2024-38616HIGHwifi: carl9170: re-fix fortified-memset warningEPSS 0.7%CVE-2026-30998HIGHAn improper resource deallocation and closure vulnerability in the tools/zmqsend.c component of FFmpeg v8.0.1 allows attackers to cause a DeEPSS 0.7%CVE-2023-45847MEDIUM Playbook Plugin Crash via Run ChecklistEPSS 0.6%CVE-2026-78551HIGHRansomLook Login Endpoint Allows Timing-Based Username Enumeration and Unthrottled Authentication AttemptsEPSS 0.6%CVE-2025-61919HIGHRack is vulnerable to a memory-exhaustion DoS through unbounded URL-encoded body parsingEPSS 0.6%CVE-2026-40140HIGHHigh-Severity Pre-Authentication Vulnerability in BeyondTrust Remote Support and Privileged Remote AccessEPSS 0.6%CVE-2022-41770MEDIUMBIG-IP and BIG-IQ iControl REST vulnerability CVE-2022-41770EPSS 0.6%CVE-2026-49293HIGHCPU exhaustion via O(n^2) BigInt construction on radix-prefixed integer literalsEPSS 0.6%CVE-2026-49476HIGHSoup Sieve: Memory Exhaustion via Large Comma-Separated Selector Lists in soupsieveEPSS 0.6%CVE-2026-56816HIGHNetty: Memory Exhaustion via HTTP/3 Reserved Frame TypesEPSS 0.6%CVE-2022-20691MEDIUMA vulnerability in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Adaptive Telephone Adapter firmware could allow an unaEPSS 0.6%CVE-2026-49477HIGHSoup Sieve: Regular Expression Denial of Service (ReDoS) in soupsieve Selector ParserEPSS 0.6%CVE-2026-59941MEDIUMDompdf: Uncontrolled resource consumption based on declared BMP dimensionsEPSS 0.6%CVE-2026-30653HIGHAn issue in Free5GC v.4.2.0 and before allows a remote attacker to cause a denial of service via the function HandleAuthenticationFailure ofEPSS 0.6%