Falhas do tipo CWE-400

3.026 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2026-31247HIGHDocling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks thru 2.61.0. The backend uses etree.parse() to parse XML fileEPSS 0.5%CVE-2026-48208MEDIUMDenial-of-Service via SVG Rendering in TicketEPSS 0.5%CVE-2025-24235MEDIUMA memory initialization issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, mEPSS 0.5%CVE-2026-41324HIGHbasic-ftp vulnerable to denial of service via unbounded memory consumption in Client.list()EPSS 0.5%CVE-2026-89147HIGHNet-SNMP through 5.9.5.2 Denial of Service via Blocking Unauthenticated SMUX ReadEPSS 0.5%CVE-2026-42583HIGHNetty: Lz4FrameDecoder resource exhaustionEPSS 0.5%CVE-2026-33375MEDIUMGrafana MSSQL Data Source Plugin: Restriction Bypass Leading to OOM DoSEPSS 0.5%CVE-2024-53693HIGHQTS, QuTS heroEPSS 0.5%CVE-2025-50095MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 9.0.0-9.EPSS 0.5%CVE-2023-33958MEDIUMDefault `maxSignatureAttempts` in `notation verify` enables an endless data attack in notationEPSS 0.5%CVE-2025-55521MEDIUMAn issue in the component /settings/localisation of Akaunting v3.1.18 allows authenticated attackers to cause a Denial of Service (DoS) via EPSS 0.5%CVE-2025-9465HIGHArmorStart® LT - Multiple Denial-of-Service VulnerabilitiesEPSS 0.5%CVE-2024-56921HIGHAn issue was discovered in Open5gs v2.7.2. InitialUEMessage, Registration request sent at a specific time can crash AMF due to incorrect errEPSS 0.5%CVE-2025-26481HIGHDell PowerScale OneFS, versions 9.4.0.0 through 9.9.0.0, contains an uncontrolled resource consumption vulnerability. A remote unprivileged EPSS 0.5%CVE-2025-52961HIGHJunos OS Evolved: PTX Series except PTX10003: An unauthenticated adjacent attacker sending specific valid traffic can cause a memory leak in cfmman leading to FPC crash and restartEPSS 0.5%CVE-2024-44160HIGHA buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7, macOS VentuEPSS 0.5%CVE-2025-25374HIGHIn NASA cFS (Core Flight System) Aquila, it is possible to put the onboard software in a state that will prevent the launch of any external EPSS 0.5%CVE-2026-33605HIGHAn unauthenticated attacker can crash the ManageSieve login process by sending a small malformed command before authenticating. If running iEPSS 0.5%CVE-2026-46689HIGHKanidm: Unauthenticated process abort via SCIM filter stack exhaustionEPSS 0.5%CVE-2026-42391HIGHAn unauthenticated attacker can send an IMAP ID command with a very large number of parameters before logging in, which causes memory and CPEPSS 0.5%