Falhas do tipo CWE-400

3.008 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2023-23689MEDIUM Dell PowerScale nodes A200, A2000, H400, H500, H600, H5600, F800, F810 integrated hardware management software contains an uncontrolled resEPSS 0.6%CVE-2023-22400HIGHJunos OS Evolved: A specific SNMP GET operation and a specific CLI commands cause resources to leak and eventually the evo-pfemand process will crashEPSS 0.6%CVE-2026-45766HIGHSuricata nfs: unbounded stateful structures can lead to resource exhaustionEPSS 0.6%CVE-2026-67318MEDIUMaxios 1.13.0 before 1.18.0 maxBodyLength Bypass via HTTP/2EPSS 0.6%CVE-2023-1580HIGHUncontrolled resource consumption in the logging feature in Devolutions Gateway 2023.1.1 and earlier allows an attacker to cause a denial ofEPSS 0.6%CVE-2026-50193MEDIUMjackson-databind: Deeply nested JsonNode throws StackOverflowError for toString()EPSS 0.6%CVE-2026-59886HIGHpyasn1: Uncontrolled resource consumption when converting decoded REAL valuesEPSS 0.6%CVE-2023-35053HIGHIn JetBrains YouTrack before 2023.1.10518 a DoS attack was possible via Helpdesk formsEPSS 0.6%CVE-2026-53965MEDIUMMCP PHP SDK: Unbounded SSE buffer in HttpTransport enables client-side denial of serviceEPSS 0.6%CVE-2025-5895MEDIUMMetabase dom.js parseDataUri redosEPSS 0.6%CVE-2024-30170HIGHPrivX before 34.0 allows data exfiltration and denial of service via the REST API. This is fixed in minor versions 33.1, 32.3, 31.3, and latEPSS 0.6%CVE-2026-32936HIGHCoreDNS DoH GET path missing size validation causes CPU and memory amplificationEPSS 0.6%CVE-2024-8454MEDIUMPLANET Technology switch devices - Swctrl service DoS attackEPSS 0.6%CVE-2023-28763MEDIUMDenial of Service in SAP NetWeaver AS for ABAP and ABAP PlatformEPSS 0.6%CVE-2026-33750MEDIUMbrace-expansion: Zero-step sequence causes process hang and memory exhaustionEPSS 0.6%CVE-2023-27270MEDIUMDenial of Service (DoS) in SAP NetWeaver AS for ABAP and ABAP PlatformEPSS 0.6%CVE-2023-25618MEDIUMDenial of Service (DoS) vulnerability in SAP NetWeaver AS for ABAP and ABAP PlatformEPSS 0.6%CVE-2023-20259HIGHA vulnerability in an API endpoint of multiple Cisco Unified Communications Products could allow an unauthenticated, remote attacker to causEPSS 0.6%CVE-2026-21452HIGHMessagePack-Java Vulnerable to Remote Denial of Service via Malicious .msgpack Model File Triggering Unbounded EXT Payload AllocationEPSS 0.6%CVE-2026-71310MEDIUMrclone: Unbounded HTTP CONNECT Response Headers Can Exhaust rclone MemoryEPSS 0.6%