Falhas do tipo CWE-400

3.000 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2026-5986MEDIUMZod jsVideoUrlParser util.js getTime redosEPSS 0.6%CVE-2026-84886MEDIUMsimular-ai Agent-S OCR HTTP API ocr_server.py ImageData resource consumptionEPSS 0.6%CVE-2026-19830MEDIUMTRENDnet TEW-816DRM bftpd bftpd.conf allocation of resourcesEPSS 0.6%CVE-2024-21651HIGHXWiki Denial of Service attack through attachmentsEPSS 0.6%CVE-2023-50019MEDIUMAn issue was discovered in open5gs v2.6.6. InitialUEMessage, Registration request sent at a specific time can crash AMF due to incorrect errEPSS 0.6%CVE-2026-67437HIGHOliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)EPSS 0.6%CVE-2026-70646HIGHaiosend: Deserialization of request body before signature verification (Pre-auth DoS) in webhook handlerEPSS 0.6%CVE-2023-26597HIGHController DOS on sending error responseEPSS 0.6%CVE-2023-34397HIGHMercedes Benz head-unit NTG 6 contains functions to import or export profile settings over USB. During parsing you can trigger that the servEPSS 0.6%CVE-2023-43767—Certain WithSecure products allow Denial of Service via the aepack archive unpack handler. This affects WithSecure Client Security 15, WithSEPSS 0.6%CVE-2023-37263MEDIUMStrapi's field level permissions not being respected in relationship titleEPSS 0.6%CVE-2026-63016MEDIUMApache InLong: Ordinary users can create new packagesEPSS 0.6%CVE-2022-41568HIGHLINE client for iOS before 12.17.0 might be crashed by sharing an invalid shared key of e2ee in group chat.EPSS 0.6%CVE-2026-40481HIGHmonetr: Unauthenticated Stripe webhook reads attacker-sized request bodies before signature validationEPSS 0.6%CVE-2023-21925MEDIUMVulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (component: Core). Supported versions thaEPSS 0.6%CVE-2023-48369MEDIUMLog Flooding due to specially crafted requests in different endpointsEPSS 0.6%CVE-2022-24118CRITICALCertain General Electric Renewable Energy products allow attackers to use a code to trigger a reboot into the factory default configuration.EPSS 0.6%CVE-2025-25186MEDIUMNet::IMAP vulnerable to possible DoS by memory exhaustionEPSS 0.6%CVE-2026-69213HIGHHttp4s Ember HTTP/2: unbounded outbound frame queueEPSS 0.6%CVE-2026-85721HIGHAsyncHttpClient: Unbounded HTTP/1.1 response decompression enables a decompression-bomb denial of serviceEPSS 0.6%