Falhas do tipo CWE-400

3.026 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2024-53458HIGHSysax Multi Server 6.99 is vulnerable to a denial of service (DoS) condition when processing specially crafted SSH packets.EPSS 0.5%CVE-2025-20162HIGHA vulnerability in the DHCP snooping security feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a fuEPSS 0.5%CVE-2026-6780HIGHDenial-of-service in the Audio/Video: Playback componentEPSS 0.5%CVE-2026-4726HIGHDenial-of-service in the XML componentEPSS 0.5%CVE-2025-43772HIGHKaleo Forms Admin in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.4 GA, 7.3 GA through update 27, and older unsupported versions EPSS 0.5%CVE-2026-10143HIGHkafka-python prior to 2.3.2 DoS via SCRAM Iteration Count in scram.pyEPSS 0.5%CVE-2025-3602HIGHLiferay Portal 7.4.0 through 7.4.3.97, and Liferay DXP 2023.Q3.1 through 2023.Q3.2, 7.4 GA through update 92, 7.3 GA through update 35, and EPSS 0.5%CVE-2026-4727HIGHDenial-of-service in the Libraries component in NSSEPSS 0.5%CVE-2026-6781HIGHDenial-of-service in the Audio/Video: Playback componentEPSS 0.5%CVE-2023-35191MEDIUMUncontrolled resource consumption for some Intel(R) SPS firmware versions may allow a privileged user to potentially enable denial of servicEPSS 0.5%CVE-2026-34593HIGHAsh Framework: Ash.Type.Module.cast_input/2 atom exhaustion via unchecked Module.concat allows BEAM VM crashEPSS 0.5%CVE-2026-33155HIGHDeepDiff has Memory Exhaustion DoS through SAFE_TO_IMPORTEPSS 0.5%CVE-2025-55634HIGHIncorrect access control in the RTMP server settings of Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_250EPSS 0.5%CVE-2026-82235HIGHfilebrowser through 2.63.23 Denial of Service via named pipesEPSS 0.5%CVE-2023-36841HIGHJunos OS: MX Series: Receipt of malformed TCP traffic will cause a Denial of ServiceEPSS 0.5%CVE-2023-48297HIGHDiscourse vulnerable to unlimited mentioned users in message serializerEPSS 0.5%CVE-2023-45956HIGHAn issue discovered in Govee LED Strip v3.00.42 allows attackers to cause a denial of service via crafted Move and MoveWithOnoff commands.EPSS 0.5%CVE-2026-33287HIGHLiquidJS has Exponential Memory Amplification through its replace_first Filter $& PatternEPSS 0.5%CVE-2024-34045HIGHThe O-RAN E2T I-Release Prometheus metric Increment function can crash in sctpThread.cpp for message.peerInfo->counters[IN_INITI][MSG_COUNTEEPSS 0.5%CVE-2025-58157HIGHgnark affected by denial of service when computing scalar multiplication using fake-GLV algorithmEPSS 0.5%