Falhas do tipo CWE-400

3.026 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2025-69873LOWajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is enaEPSS 0.5%CVE-2026-42212HIGHSolidCAM-GPPL-IDE: XML External Entity (XXE) and billion-laughs DoS in VMID parserEPSS 0.5%CVE-2026-65410HIGHThe issue was addressed with improved checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, mEPSS 0.5%CVE-2023-5330MEDIUM Denial of Service via Opengraph Data CacheEPSS 0.5%CVE-2020-36872HIGHBACnet Test Server 1.01 Malformed BVLC Length DoSEPSS 0.5%CVE-2025-61025HIGHAn issue in the sslr_qst_get component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via craftEPSS 0.5%CVE-2026-91867MEDIUMApache Neethi: Remote policy fetch lacks a total timeout, allowing a slow server to hang the request indefinitelyEPSS 0.5%CVE-2025-71031HIGHWater-Melon Melon commit 9df9292 and below is vulnerable to Denial of Service. The HTTP component doesn't have any maximum length. As a resuEPSS 0.5%CVE-2024-12698MEDIUMOse-olm-catalogd-container: incomplete fix for rapid reset (cve-2023-39325/cve-2023-44487)EPSS 0.5%CVE-2024-57076HIGHA prototype pollution in the lib.post function of ajax-request v1.2.3 allows attackers to cause a Denial of Service (DoS) via supplying a crEPSS 0.5%CVE-2024-57081HIGHA prototype pollution in the lib.fromQuery function of underscore-contrib v0.3.0 allows attackers to cause a Denial of Service (DoS) via supEPSS 0.5%CVE-2020-1687MEDIUMJunos OS: EX4300-MP/EX4600/QFX5K Series: High CPU load due to receipt of specific layer 2 frames in EVPN-VXLAN deployment.EPSS 0.5%CVE-2023-34109MEDIUMUser input results in Unbounded resource consumption in @zxcvbn-ts/coreEPSS 0.5%CVE-2025-50102MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.EPSS 0.5%CVE-2025-59471MEDIUMA denial of service vulnerability exists in self-hosted Next.js applications that have `remotePatterns` configured for the Image Optimizer. EPSS 0.5%CVE-2026-26937MEDIUMUncontrolled Resource Consumption in Kibana Leading to Denial of ServiceEPSS 0.5%CVE-2026-25791HIGHSliver has a DNS C2 OTP Bypass Allows Unauthenticated Session Flooding and Denial of ServiceEPSS 0.5%CVE-2026-61155CRITICALVulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge). The supported version EPSS 0.5%CVE-2024-58306HIGHminaliC 2.0.0 Denial of Service Vulnerability via Large GET RequestEPSS 0.5%CVE-2023-5876LOWRegex DoS from a malicious server enrolled in DesktopEPSS 0.5%