Falhas do tipo CWE-400

3.026 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2025-35432MEDIUMCISA Thorium does not rate limit account verification email messagesEPSS 0.6%CVE-2022-48475HIGHBuffer Overflow vulnerability in Control de Ciber version 1.650, in the printing function. Sending a modified request by the attacker could EPSS 0.6%CVE-2025-61771HIGHRack's multipart parser buffers large non‑file fields entirely in memory, enabling DoS (memory exhaustion)EPSS 0.6%CVE-2018-25100MEDIUMThe Mojolicious module before 7.66 for Perl may leak cookies in certain situations related to multiple similar cookies for the same domain. EPSS 0.6%CVE-2024-4284MEDIUMDenial of Service in mintplex-labs/anything-llmEPSS 0.6%CVE-2026-44796MEDIUMNautobot: Object bulk rename UI actions vulnerable to denial of service by crafted regular expression (REDoS)EPSS 0.6%CVE-2024-43647HIGHA vulnerability has been identified in SIMATIC S7-200 SMART CPU CR40 (6ES7288-1CR40-0AA0) (All versions), SIMATIC S7-200 SMART CPU CR60 (6ESEPSS 0.6%CVE-2025-48956HIGHvLLM API endpoints vulnerable to Denial of Service AttacksEPSS 0.6%CVE-2026-53954MEDIUMBugsink: DOS using large numbers of event tagsEPSS 0.6%CVE-2025-50093MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.0-8.0.42, EPSS 0.6%CVE-2025-67725HIGHTornado is Vulnerable to Quadratic DoS via Repeated Header CoalescingEPSS 0.6%CVE-2026-63015MEDIUMApache InLong: Non-template responsible persons can view template informationEPSS 0.6%CVE-2025-50092MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.42, 8.4.0EPSS 0.6%CVE-2024-10188HIGHDenial of Service in BerriAI/litellmEPSS 0.6%CVE-2025-20370MEDIUMDenial of Service (DoS) through Multiple LDAP Bind Requests in Splunk EnterpriseEPSS 0.6%CVE-2023-29333LOWMicrosoft Access Denial of Service VulnerabilityEPSS 0.6%CVE-2023-24594MEDIUMBIG-IP TMM SSL vulnerabilityEPSS 0.6%CVE-2024-5795HIGHDenial of Service vulnerability was identified in GitHub Enterprise Server that allowed resource exhaustionEPSS 0.6%CVE-2026-73228MEDIUMDjango REST framework: Potential bypass of Django `DATA_UPLOAD_MAX_MEMORY_SIZE` when parsing oversized JSON and urlencoded request bodies via DRF `request.data`EPSS 0.6%CVE-2023-51847HIGHAn issue in obgm and Libcoap v.a3ed466 allows a remote attacker to cause a denial of service via thecoap_context_t function in the src/coap_EPSS 0.6%