Falhas do tipo CWE-400

3.026 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2026-44630HIGHApache IoTDB: RPC service denial of service via unchecked Thrift string lengthEPSS 0.6%CVE-2022-47556MEDIUMUncontrolled Resource Consumption in Ormazabal productsEPSS 0.6%CVE-2023-39219HIGHAdmin Console Denial of Service via Java class enumerationEPSS 0.6%CVE-2026-36590HIGHAn issue in EMQ NanoMQ v.0.24.9 allows a remote attacker to cause a denial of service via the nni_qos_db_set function in broker_tcp.c componEPSS 0.6%CVE-2023-39329MEDIUMOpenjpeg: resource exhaustion will occur in the opj_t1_decode_cblks function in the tcd.cEPSS 0.6%CVE-2022-27600MEDIUMQTS, QuTS hero, QuTScloudEPSS 0.6%CVE-2025-50080MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Stored Procedure). Supported versions that are affected are 8EPSS 0.6%CVE-2026-68924MEDIUMMobSF: Zip Bomb Denial of Service via Per-File Size Limit Bypass in ZIP/APK ExtractionEPSS 0.6%CVE-2024-56940HIGHAn issue in the profile image upload function of LearnDash v6.7.1 allows attackers to cause a Denial of Service (DoS) via excessive file uplEPSS 0.6%CVE-2025-29957MEDIUMWindows Deployment Services Denial of Service VulnerabilityEPSS 0.6%CVE-2024-5216HIGHDenial of Service in mintplex-labs/anything-llmEPSS 0.6%CVE-2025-41677MEDIUMResource Exhaustion via POST Requests to send-mail ActionEPSS 0.6%CVE-2026-54268HIGHAngular: Denial of Service (DoS) via OOM in Date Formatting (formatDate)EPSS 0.6%CVE-2022-1677—In OpenShift Container Platform, a user with permissions to create or modify Routes can craft a payload that inserts a malformed entry into EPSS 0.6%CVE-2026-22259HIGHSuricata dnp3: unbounded transaction growthEPSS 0.6%CVE-2023-45196MEDIUMAdminer and AdminerEvo denial of service via HTTP redirectEPSS 0.6%CVE-2026-68005HIGHAn issue in ACME mini_httpd 1.30 and prior allows a remote attacker to cause a denial of service via the HTTP request header parser in the hEPSS 0.6%CVE-2026-52197HIGHAn issue in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_44af70 componenEPSS 0.6%CVE-2026-76646HIGHApache MyFaces: Denial of Service via Unbounded Request ParsingEPSS 0.6%CVE-2023-29139MEDIUMAn issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. When a user with checkuserlog permissions makes many CheckUEPSS 0.6%