Falhas do tipo CWE-400

3.026 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2026-51600HIGHTenda CP3 V3.0 firmware V31.1.9.91 does not validate the Content-Length header field in RTSP requests (including DESCRIBE, SETUP, and PLAY mEPSS 0.6%CVE-2025-59830HIGHRack QueryParser has an unsafe default allowing params_limit bypass via semicolon-separated parametersEPSS 0.6%CVE-2025-5889LOWjuliangruber brace-expansion index.js expand redosEPSS 0.6%CVE-2022-36326MEDIUMResource Exhaustion Vulnerability in Western Digital devicesEPSS 0.6%CVE-2024-52981MEDIUMAn issue was discovered in Elasticsearch, where a large recursion using the Well-KnownText formatted string with nested GeometryCollection oEPSS 0.6%CVE-2026-28221MEDIUMWazuh: Pre-auth stack-based buffer overflow in wazuh-remoted print_hex_string() due to signed char promotion on x86_64EPSS 0.6%CVE-2025-68272HIGHSignal K Server Vulnerable to Denial of Service via Unrestricted Access Request FloodingEPSS 0.6%CVE-2023-29185MEDIUMDenial of Service (DOS) in SAP NetWeaver AS for ABAP (Business Server Pages)EPSS 0.6%CVE-2026-92003MEDIUMMISP Unthrottled Authentication Failure Log Writes Enable Resource ExhaustionEPSS 0.6%CVE-2025-44203HIGHIn HotelDruid 3.0.0 and 3.0.7, the unauthenticated database-setup endpoint creadb.php can be reached before setup is completed and performs EPSS 0.6%CVE-2024-21526HIGHAll versions of the package speaker are vulnerable to Denial of Service (DoS) when providing unexpected input types to the channels propertyEPSS 0.6%CVE-2026-44645MEDIUMLiquidJS has a renderLimit DoS guard bypass via empty `{% for %}` bodyEPSS 0.6%CVE-2025-30752LOWVulnerability in the Oracle Java SE, Oracle GraalVM for JDK product of Oracle Java SE (component: Compiler). The supported version that isEPSS 0.6%CVE-2024-28122MEDIUM JWX vulnerable to a denial of service attack using compressed JWE messageEPSS 0.6%CVE-2026-73216MEDIUMcoturn: mobility disconnects bypass allocation quotas and exhaust relay capacityEPSS 0.6%CVE-2024-6427HIGHUncontrolled Resource Consumption vulnerability in MESbookEPSS 0.6%CVE-2026-78684MEDIUMvLLM before 0.27.0 Denial of Service via DeepStream BackendEPSS 0.6%CVE-2024-27085MEDIUMDenial of service through invites in DiscourseEPSS 0.6%CVE-2022-4344MEDIUMMemory exhaustion in the Kafka protocol dissector in Wireshark 4.0.0 to 4.0.1 and 3.6.0 to 3.6.9 allows denial of service via packet injectiEPSS 0.6%CVE-2025-56424HIGHAn issue in Insiders Technologies GmbH e-invoice pro before release 1 Service Pack 2 allows a remote attacker to cause a denial of service vEPSS 0.6%