Falhas do tipo CWE-400

3.026 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2026-55588MEDIUMORAS CLI: Cyclic Referrer Graph Can Cause Unbounded Recursion and Resource ConsumptionEPSS 0.5%CVE-2025-52322HIGHAn issue in Open5GS v2.7.2 and before allows a remote attacker to cause a denial of service via a crafted Create Session Request message to EPSS 0.5%CVE-2023-3585MEDIUMchannel DoS by sharing a boards linkEPSS 0.5%CVE-2023-34061HIGHCVE-2023-34061 – Gorouter route pruningEPSS 0.5%CVE-2026-41135HIGHfree5GC PCF: Memory Leak via CORS Middleware Registration in HTTP Handler Leads to Denial of ServiceEPSS 0.5%CVE-2026-33204HIGHSimpleJWT has an Unauthenticated Denial of Service via JWE header tamperingEPSS 0.5%CVE-2024-45736MEDIUMImproperly Formatted ‘INGEST_EVAL’ Parameter Crashes Splunk DaemonEPSS 0.5%CVE-2025-50076MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.0-8.0.25. EPSS 0.5%CVE-2024-52980MEDIUMElasticsearch Uncontrolled Resource Consumption vulnerabilityEPSS 0.5%CVE-2024-22091LOWExcessive resource consumption due to lack to request path size limitsEPSS 0.5%CVE-2026-47476HIGHNVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource consumption. A successfuEPSS 0.5%CVE-2024-54658MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOSEPSS 0.5%CVE-2025-2586HIGHOls: unauthenticated metrics flooding in openshift lightspeed service leading to resource exhaustionEPSS 0.5%CVE-2025-6493MEDIUMCodeMirror Markdown Mode markdown.js redosEPSS 0.5%CVE-2025-49722MEDIUMWindows Print Spooler Denial of Service VulnerabilityEPSS 0.5%CVE-2024-27088NONEes5-ext Regular Expression Denial of Service in `function#copy` and `function#toStringTokens`EPSS 0.5%CVE-2025-67726HIGHTornado is Vulnerable to Quadratic DoS via Crafted Multipart ParametersEPSS 0.5%CVE-2026-28351MEDIUMManipulated RunLengthDecode streams can exhaust RAMEPSS 0.5%CVE-2026-37234HIGHFlexRIC v2.0.0 allows a single SCTP connection to bind multiple xapp_ids by sending multiple E42_SETUP_REQUESTs. On disconnect, only the firEPSS 0.5%CVE-2026-74982HIGHDenial-of-service in the Widget componentEPSS 0.5%