Fallos del tipo CWE-400

3036 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2026-63261MEDIUMUncontrolled Resource Consumption in Kibana Leading to Denial of ServiceEPSS 0.5%CVE-2026-42399MEDIUMUncontrolled Resource Consumption in Kibana Leading to Denial of ServiceEPSS 0.5%CVE-2025-53538HIGHSuricata's mishandling of data on HTTP2 stream 0 can lead to resource starvationEPSS 0.5%CVE-2026-84289MEDIUMNousResearch hermes-agent MCP Tool mcp_tool.py list_tools memory allocationEPSS 0.5%CVE-2026-6601MEDIUMLagom WHMCS Template Datatables resource consumptionEPSS 0.5%CVE-2026-40924MEDIUMTekton Pipelines: HTTP Resolver Unbounded Response Body Read Enables Denial of Service via Memory ExhaustionEPSS 0.5%CVE-2026-84888MEDIUMRightNow-AI OpenFang tool_runner.rs shell_exec memory allocationEPSS 0.5%CVE-2026-33474MEDIUMVikunja Affected by DoS via Image Preview GenerationEPSS 0.5%CVE-2025-68971MEDIUMIn Forgejo through 13.0.3, the attachment component allows a denial of service by uploading a multi-gigabyte file attachment (e.g., to be asEPSS 0.5%CVE-2024-34364MEDIUMEnvoy OOM vector from HTTP async client with unbounded response buffer for mirror responseEPSS 0.5%CVE-2026-60301HIGHVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.EPSS 0.5%CVE-2026-87289HIGHVulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver-static-content). Supported versions that areEPSS 0.5%CVE-2026-46834HIGHVulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Easily exploEPSS 0.5%CVE-2026-60180HIGHVulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/C++). Supported versions that are affected are 9.7.0-9.EPSS 0.5%CVE-2026-73882HIGHVulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected aEPSS 0.5%CVE-2026-87222HIGHVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.5%CVE-2026-46862HIGHVulnerability in the MySQL Router product of Oracle MySQL (component: Router: General). Supported versions that are affected are 8.4.0-8.4.EPSS 0.5%CVE-2026-46863HIGHVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Connection Handling). Supported versions that EPSS 0.5%CVE-2026-83222HIGHVulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affEPSS 0.5%CVE-2026-87277HIGHVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.5%