Falhas do tipo CWE-400

3.008 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2024-37299MEDIUMDiscourse vulnerable to DoS via Tag GroupEPSS 0.6%CVE-2025-48392HIGHApache IoTDB: DoS VulnerabilityEPSS 0.6%CVE-2026-55512MEDIUMnebula-mesh: Unauthenticated OIDC login endpoint allocates unbounded in-memory state entries without rate limitingEPSS 0.6%CVE-2024-21521HIGHAll versions of the package @discordjs/opus are vulnerable to Denial of Service (DoS) due to providing an input object with a property toStrEPSS 0.6%CVE-2024-23824MEDIUMmailcow ipixel flood attack leads to Denial of Service in admin pageEPSS 0.6%CVE-2025-9283HIGHArmorStart® LT - Multiple Denial-of-Service VulnerabilitiesEPSS 0.6%CVE-2025-9282HIGHArmorStart® LT - Multiple Denial-of-Service VulnerabilitiesEPSS 0.6%CVE-2025-9281HIGHArmorStart® LT - Multiple Denial-of-Service VulnerabilitiesEPSS 0.6%CVE-2025-43462HIGHThe issue was addressed with improved memory handling. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOEPSS 0.6%CVE-2025-9279HIGHArmorStart® LT - Multiple Denial-of-Service VulnerabilitiesEPSS 0.6%CVE-2026-30041HIGHAn integer overflow in the PSD parser compnent of FastStone Image Viewer v8.3 allows attackers to execute arbitrary code or cause a Denial oEPSS 0.6%CVE-2026-74789HIGHScriban before 7.0.0 LoopLimit Bypass via Built-in OperationsEPSS 0.6%CVE-2026-28435HIGHPayload size limit bypass via gzip decompression in ContentReader (streaming) allows oversized request bodies in cpp-httplibEPSS 0.6%CVE-2022-46315HIGHThe ProfileSDK has defects introduced in the design process. Successful exploitation of this vulnerability may affect system availability. EPSS 0.6%CVE-2026-33285HIGHLiquidJS: memoryLimit Bypass through Negative Range Values Leads to Process CrashEPSS 0.6%CVE-2025-26782HIGHAn issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330,EPSS 0.6%CVE-2024-55568HIGHAn issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380,EPSS 0.6%CVE-2025-21547CRITICALVulnerability in the Oracle Hospitality OPERA 5 product of Oracle Hospitality Applications (component: Opera Servlet). Supported versions tEPSS 0.6%CVE-2026-92879MEDIUMvgmstream mus_acm.c parse_mus resource consumptionEPSS 0.6%CVE-2026-86515MEDIUMvgmstream txtp txtp_parser.c add_entry resource consumptionEPSS 0.6%