Falhas do tipo CWE-400

3.026 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2025-53067MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 9.0.0-9.EPSS 0.6%CVE-2025-53042MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.EPSS 0.6%CVE-2025-53040MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.EPSS 0.6%CVE-2026-26673HIGHAn issue in DJI Mavic Mini, Spark, Mavic Air, Mini, Mini SE 0.1.00.0500 and below allows a remote attacker to cause a denial of service via EPSS 0.6%CVE-2022-28639HIGHA remote potential adjacent denial of service (DoS) and potential adjacent arbitrary code execution vulnerability that could potentially leaEPSS 0.6%CVE-2024-12601MEDIUMCalculated Fields Form <= 5.2.63 - Denial of ServiceEPSS 0.6%CVE-2024-46923HIGHAn issue was discovered in Samsung Mobile Processor Exynos 2200, 1480, and 2400. The absence of a null check leads to a Denial of Service atEPSS 0.6%CVE-2026-73214HIGHcoturn allocates a full per-peer SSL/session before verifying the DTLS cookie, enabling source-spoofing/botnet state-exhaustion DoSEPSS 0.6%CVE-2024-47003LOWDoS via non-string message using permalink embedEPSS 0.6%CVE-2024-6434LOWPremium Addons for Elementor <= 4.10.35 - Regular Expressions Denial of ServiceEPSS 0.6%CVE-2024-47210HIGHGladys Assistant before 4.45.1 allows Privilege Escalation (a user changing their own role) because req.body.role can be used in updateMySelEPSS 0.6%CVE-2026-31051LOWAn issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to cause a denial of service via the Client Balance componentEPSS 0.6%CVE-2025-63235HIGHIn sol commit 373d848 (2024-12-12), the broker does not fully release resources when handling malformed or duplicate CONNECT packets. When cEPSS 0.6%CVE-2023-4063MEDIUMCertain HP OfficeJet Pro printers are potentially vulnerable to a Denial of Service when using an improper eSCL URL GET request.EPSS 0.6%CVE-2024-57075HIGHA prototype pollution in the lib.Logger function of eazy-logger v4.0.1 allows attackers to cause a Denial of Service (DoS) via supplying a cEPSS 0.6%CVE-2026-73715HIGHUnauthenticated Denial-of-Service (DoS) Vulnerability in the API of HPE Networking Fabric ComposerEPSS 0.6%CVE-2026-73786HIGHUnauthenticated Network-Based Denial of Service in CPPM systemsEPSS 0.6%CVE-2025-59830HIGHRack QueryParser has an unsafe default allowing params_limit bypass via semicolon-separated parametersEPSS 0.6%CVE-2026-70489MEDIUMOpen WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsingEPSS 0.6%CVE-2026-45047HIGHbird-lg-go: Fatal Out-of-Memory (OOM) Denial of Service via Unbounded JSON DecodingEPSS 0.6%