Falhas do tipo CWE-400

3.026 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2025-41676MEDIUMResource Exhaustion via POST Requests to send-sms ActionEPSS 0.6%CVE-2026-16836HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.5%CVE-2026-9171HIGHVulnerabilities in IBM WebSphere Application affects IBM PowerVM Novalink.EPSS 0.5%CVE-2026-23842HIGHChatterBot has Denial of Service via Database Connection Pool ExhaustionEPSS 0.5%CVE-2026-36478HIGHAn issue in Technitium DNS Server v.14.3 and before allows a remote attacker to cause a denial of service via the DnsServerApp.exe, DnsServeEPSS 0.5%CVE-2026-16824HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.5%CVE-2026-17121HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.5%CVE-2023-1206—A hash collision flaw was found in the IPv6 connection lookup table in the Linux kernel’s IPv6 functionality when a user makes a new kind ofEPSS 0.5%CVE-2026-16818HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.5%CVE-2026-16831HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.5%CVE-2026-16690HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.5%CVE-2026-9165HIGHStackrox: stackrox: unbounded graphql query depth allows authenticated denial of serviceEPSS 0.5%CVE-2026-73559MEDIUMvLLM: Completion prompt lists fan out into unbounded engine requestsEPSS 0.5%CVE-2026-86734HIGHSnipe-IT before 8.7.1 Denial of Service via Unbounded Note FieldEPSS 0.5%CVE-2025-30158HIGHNamelessMC Forum iframe width/height abuse causing UI-based Denial of ServiceEPSS 0.5%CVE-2026-69147MEDIUMvLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservationEPSS 0.5%CVE-2026-54092MEDIUMFile Browser: DoS Vulnerability on Public Login APIEPSS 0.5%CVE-2026-83600MEDIUMNetdata: Streaming protocol chart slot guard off-by-one allows ~16 GiB allocation request, crashing parent agentEPSS 0.5%CVE-2025-31118HIGHNamelessMC Has Forum Reply Submission Time Limit BypassEPSS 0.5%CVE-2026-52814MEDIUMGogs: Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion)EPSS 0.5%