Falhas do tipo CWE-400

3.008 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2026-94640HIGHRpcbind: unbounded memory allocation in rpcbind statistics tracking allows unauthenticated remote denial of serviceEPSS 0.6%CVE-2024-22332MEDIUMIBM Integration Bus for z/OS denial of serviceEPSS 0.6%CVE-2026-45713HIGHMailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizesEPSS 0.6%CVE-2025-5896MEDIUMtarojs taro index.js redosEPSS 0.6%CVE-2023-32341MEDIUMIBM Sterling B2B Integrator denial of serviceEPSS 0.6%CVE-2026-0889HIGHDenial-of-service in the DOM: Service Workers componentEPSS 0.6%CVE-2024-27800HIGHThis issue was addressed by removing the vulnerable code. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macEPSS 0.6%CVE-2022-37907MEDIUMA vulnerability exists in the ArubaOS bootloader on 7xxx series controllers which can result in a denial of service (DoS) condition on an imEPSS 0.6%CVE-2024-11498MEDIUMResource exhaustion via Stack overflow in libjxlEPSS 0.6%CVE-2026-18549HIGH@fastify/multipart vulnerable to Denial of Service via aborted upload after fileSize limitEPSS 0.6%CVE-2025-5892MEDIUMRocketChat parseMessage.js parseMessage redosEPSS 0.6%CVE-2025-5897MEDIUMvuejs vue-cli Markdown Code HtmlPwaPlugin.js HtmlPwaPlugin redosEPSS 0.6%CVE-2024-21523HIGHAll versions of the package images are vulnerable to Denial of Service (DoS) due to providing unexpected input types to several different fuEPSS 0.6%CVE-2023-42503—Apache Commons Compress: Denial of service via CPU consumption for malformed TAR fileEPSS 0.6%CVE-2024-27354HIGHAn issue was discovered in phpseclib 1.x before 1.0.23, 2.x before 2.0.47, and 3.x before 3.0.36. An attacker can construct a malformed certEPSS 0.6%CVE-2023-23524HIGHA denial-of-service issue was addressed with improved input validation. This issue is fixed in tvOS 16.3.2, iOS 16.3.1 and iPadOS 16.3.1, waEPSS 0.6%CVE-2023-2785MEDIUMSpecially crafted search query can cause large log entries in postgresEPSS 0.6%CVE-2025-8537MEDIUMAxiomatic Bento4 mp4decrypt Mp4Decrypt.cpp SetDataSize allocation of resourcesEPSS 0.6%CVE-2024-47497HIGHJunos OS: SRX Series, QFX Series, MX Series and EX Series: Receiving specific HTTPS traffic causes resource exhaustionEPSS 0.6%CVE-2021-23047—On version 16.x before 16.1.0, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.3, and all versions of 13.1.x, 12.1.x and 11.6.x, when BIG-IP APEPSS 0.6%