Falhas do tipo CWE-400

3.026 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2025-21547CRITICALVulnerability in the Oracle Hospitality OPERA 5 product of Oracle Hospitality Applications (component: Opera Servlet). Supported versions tEPSS 0.6%CVE-2026-86515MEDIUMvgmstream txtp txtp_parser.c add_entry resource consumptionEPSS 0.6%CVE-2026-92879MEDIUMvgmstream mus_acm.c parse_mus resource consumptionEPSS 0.6%CVE-2023-26437LOWDeterred spoofing attempts can lead to authoritative servers being marked unavailableEPSS 0.6%CVE-2024-25355HIGHs3-url-parser 1.0.3 is vulnerable to Denial of service via the regexes component.EPSS 0.6%CVE-2024-34084HIGHMinder's Github Webhook Handler vulnerable to denial of service from un-validated requestsEPSS 0.6%CVE-2024-24827MEDIUMNo rate limits on POST /uploads endpoint in DiscourseEPSS 0.6%CVE-2023-45955—An issue discovered in Nanoleaf Light strip v3.5.10 allows attackers to cause a denial of service via crafted write binding attribute commanEPSS 0.6%CVE-2026-33268MEDIUMNanoleaf Lines unauthenticated firmware file storeEPSS 0.6%CVE-2025-50079MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.EPSS 0.6%CVE-2025-50089MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 9.0.0-9.EPSS 0.6%CVE-2025-50091MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.EPSS 0.6%CVE-2025-50077MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.42, 8.4.0EPSS 0.6%CVE-2024-27686HIGHMikrotik RouterOS (x86) 6.40.5 through 6.49.10 (fixed in 7) allows a remote attacker to cause a denial of service (device crash) via craftedEPSS 0.6%CVE-2025-55796HIGHThe openml/openml.org web application version v2.0.20241110 uses predictable MD5-based tokens for critical user workflows such as signup conEPSS 0.6%CVE-2025-0191MEDIUMDenial of Service in gaizhenbiao/chuanhuchatgptEPSS 0.6%CVE-2026-33169MEDIUMRails Active Support has a possible ReDoS vulnerability in number_to_delimitedEPSS 0.6%CVE-2026-83614HIGHxmldom: Quadratic-time parsing via the malformed-input recovery path — `parseElementStartPart` re-scan and `normalize()` adjacent-text mergeEPSS 0.6%CVE-2026-73413HIGHShescape: Quadratic-time denial of service in flag-protectionEPSS 0.6%CVE-2026-40303HIGHzrok allows unauthenticated DoS via unbounded memory allocation in striped session cookie parsingEPSS 0.6%