Falhas do tipo CWE-400

3.026 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2026-30405HIGHAn issue in GoBGP gobgpd v.4.2.0 allows a remote attacker to cause a denial of service via the NEXT_HOP path attributeEPSS 0.5%CVE-2025-21549HIGHVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). The supported version that is affected EPSS 0.5%CVE-2026-48937MEDIUMA flaw in Node.js HTTP/2 server API can cause servers to keep accepting data even after sending a `GOAWAY` frame. This vulnerability affectsEPSS 0.5%CVE-2024-3056HIGHPodman: kernel: containers in shared ipc namespace are vulnerable to denial of service attackEPSS 0.5%CVE-2026-92363MEDIUMag-ui-protocol ag-ui JSON sse_parser.cpp resource consumptionEPSS 0.5%CVE-2026-85100MEDIUM2FastLabs agent-squad Streaming Agent Response Workflow orchestrator.ts AgentSquad.routeRequest resource consumptionEPSS 0.5%CVE-2026-50018MEDIUMHoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve ActionsEPSS 0.5%CVE-2024-7567MEDIUMRockwell Automation Micro850/870 Vulnerable to denial-of-service Vulnerability via CIP/Modbus PortEPSS 0.5%CVE-2026-86452HIGHMISP Unauthenticated Mail Endpoints Allow Unbounded Storage Consumption and Request FloodingEPSS 0.5%CVE-2026-44240HIGHbasic-ftp allows a malicious FTP server to cause client-side denial of service via unbounded multiline control response bufferingEPSS 0.5%CVE-2025-50083MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.EPSS 0.5%CVE-2026-46627HIGHTwig: Sandbox resource exhaustion via unbounded `for` / `range()`EPSS 0.5%CVE-2023-23925HIGHSwitcher Client contains Regular Expression Denial of Service (ReDoS)EPSS 0.5%CVE-2024-34688HIGHDenial of service (DOS) in SAP NetWeaver AS Java (Meta Model Repository)EPSS 0.5%CVE-2025-55972HIGHA TCL Smart TV running a vulnerable UPnP/DLNA MediaRenderer implementation is affected by a remote, unauthenticated Denial of Service (DoS) EPSS 0.5%CVE-2026-28872HIGHA resource exhaustion issue was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and EPSS 0.5%CVE-2026-21696HIGHEndless reprocessing/reupload of activity log data due to SQLite max parameters limit not being consideredEPSS 0.5%CVE-2023-26157MEDIUMVersions of the package libredwg before 0.12.5.6384 are vulnerable to Denial of Service (DoS) due to an out-of-bounds read involving sectionEPSS 0.5%CVE-2025-44650HIGHIn Netgear R7000 V1.3.1.64_10.1.36 and EAX80 V1.0.1.70_1.0.2, the USERLIMIT_GLOBAL option is set to 0 in the bftpd.conf configuration file. EPSS 0.5%CVE-2022-24902LOWMemory issue in playing videosEPSS 0.5%