Falhas do tipo CWE-400

3.000 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2026-56816HIGHNetty: Memory Exhaustion via HTTP/3 Reserved Frame TypesEPSS 0.6%CVE-2026-14257HIGHbrace-expansion DoS via unbounded expansion length causing an out-of-memory process crashEPSS 0.6%CVE-2023-47150HIGHIBM Common Cryptographic Architecture denial of serviceEPSS 0.6%CVE-2026-48050HIGHArc: Unauthenticated access to Go debug pprof endpoints leaks runtime state and enables CPU-burn DoSEPSS 0.6%CVE-2023-49809MEDIUMTodo plugin gets crashed and disabled by memberEPSS 0.6%CVE-2025-9466HIGHArmorStart® LT - Multiple Denial-of-Service VulnerabilitiesEPSS 0.6%CVE-2024-34953HIGHAn issue in taurusxin ncmdump v1.3.2 allows attackers to cause a Denial of Service (DoS) via memory exhaustion by supplying a crafted .ncm fEPSS 0.6%CVE-2025-3526HIGHSessionClicks in Liferay Portal 7.0.0 through 7.4.3.21, and Liferay DXP 7.4 GA through update 9, 7.3 GA through update 25, and older unsuppoEPSS 0.6%CVE-2023-27314HIGHDenial of Service Vulnerability in ONTAP 9EPSS 0.6%CVE-2025-5891MEDIUMUnitech pm2 Config.js redosEPSS 0.6%CVE-2025-3986MEDIUMApereo CAS CasConfigurationMetadataServerController.java redosEPSS 0.6%CVE-2023-46737LOWPossible endless data attack from attacker-controlled registry in cosignEPSS 0.6%CVE-2026-25762HIGHAdonisJS vulnerable to Denial of Service (DoS) via Unrestricted Memory Buffering in PartHandler during File Type DetectionEPSS 0.6%CVE-2026-64868HIGHNew API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body loggingEPSS 0.6%CVE-2025-61920HIGHAuthlib is vulnerable to Denial of Service via Oversized JOSE SegmentsEPSS 0.6%CVE-2021-47368HIGHenetc: Fix illegal access when reading affinity_hintEPSS 0.6%CVE-2026-5986MEDIUMZod jsVideoUrlParser util.js getTime redosEPSS 0.6%CVE-2026-15308HIGHIncremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarationsEPSS 0.6%CVE-2026-8319MEDIUMaiwaves-cn agents cheshire_cat_core stray_cat.py recall_relevant_memories_to_working_memory resource consumptionEPSS 0.6%CVE-2026-21728HIGHTempo query limit results in unbounded memory allocationEPSS 0.6%