Falhas do tipo CWE-400

3.026 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2024-38520MEDIUMSoftEther VPN with L2TP - 2.75x AmplificationEPSS 0.5%CVE-2025-30476MEDIUMDell PowerScale InsightIQ, version 5.2, contains an uncontrolled resource consumption vulnerability. An unauthenticated attacker with remoteEPSS 0.5%CVE-2025-21545HIGHVulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch). Supported versions that are afEPSS 0.5%CVE-2025-6921MEDIUMRegular Expression Denial of Service (ReDoS) in huggingface/transformersEPSS 0.5%CVE-2025-67133HIGHAn issue in Hero Motocorp Vida V1 Pro 2.0.7 allows a local attacker to cause a denial of service via the BLE componentEPSS 0.5%CVE-2021-44319HIGHParrot AR.Drone 1 and AR.Drone 2 are vulnerable to Denial of Service. The Parrot AR.Drone platform is vulnerable to Wi-Fi deauthentication aEPSS 0.5%CVE-2026-55520HIGHProtego: Exponential backtracking ReDoS in robots.txt URL wildcard matchingEPSS 0.5%CVE-2026-28874HIGHThe issue was addressed with improved checks. This issue is fixed in iOS 26.4 and iPadOS 26.4. A remote attacker may cause an unexpected appEPSS 0.5%CVE-2026-85107MEDIUMNousResearch hermes-agent Electron Main Process main.ts resourceBufferFromUrl allocation of resourcesEPSS 0.5%CVE-2026-84833MEDIUMntegrals openbrowser Browser Agent Message Construction agent.ts resource consumptionEPSS 0.5%CVE-2025-53023MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are 8.0.0-EPSS 0.5%CVE-2020-1668MEDIUMJunos OS: EX2300 Series: High CPU load due to receipt of specific multicast packets on layer 2 interfaceEPSS 0.5%CVE-2025-50094MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.42, 8.4.5 EPSS 0.5%CVE-2026-79658HIGHEch0 before 5.0.1 Denial of Service via Accept-LanguageEPSS 0.5%CVE-2026-33232HIGHAutoGPT: Unauthenticated DoS via Disk Space ExhaustionEPSS 0.5%CVE-2026-87908HIGHmultiparty vulnerable to Denial of Service via unbounded part-header accumulationEPSS 0.5%CVE-2026-85585HIGHSiYuan before v3.8.2 Unbounded Memory Consumption via ControlConcurrencyEPSS 0.5%CVE-2023-45810MEDIUMOpenFGA denial of serviceEPSS 0.5%CVE-2026-67855HIGHopen62541 contains a heap use-after-free in the GDS PushManagement certificate update workflow when UA_ENABLE_GDS_PUSHMANAGEMENT is enabled.EPSS 0.5%CVE-2026-41680HIGHMarked: OOM Denial of Service via Infinite Recursion in marked TokenizerEPSS 0.5%