Fallos del tipo CWE-400

3039 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2025-21548MEDIUMVulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python). Supported versions that are affected are 9.1.0EPSS 0.5%CVE-2023-43786MEDIUMLibx11: stack exhaustion from infinite recursion in putsubimage()EPSS 0.5%CVE-2026-75371HIGHAn integer handling flaw in the cobs_decode function of SpaceDot AcubeSAT OBC software commit eaf90ec allows physically-proximate attackers EPSS 0.5%CVE-2026-50879HIGHAn issue in the uploadPostHandler component of Andrei Marcu linx-server v2.3.8 allows attackers to cause a Denial of Service (DoS) via a craEPSS 0.5%CVE-2026-70906HIGHVulnerability in Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 25.0.4 and 26.0.2. Easily exploiEPSS 0.5%CVE-2026-83280HIGHVulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver-http2). Supported versions that are affectedEPSS 0.5%CVE-2026-42544HIGHGranian: Unauthenticated DoS via WebSocket subprotocol header panicEPSS 0.5%CVE-2025-63913HIGHAn issue was discovered in OpenSBI 1.3 allowing attackers to cause a denial of service via crafted request to the SBI function #2 or the 'FiEPSS 0.5%CVE-2026-34826MEDIUMRack: Unbounded Range Count in get_byte_ranges Enables DoSEPSS 0.5%CVE-2026-88286HIGHGV-LPC2011/LPC2211 - PTZ Connection-State Accept-Loop Denial of ServiceEPSS 0.5%CVE-2026-42342HIGHReact Router vulnerable to DoS via unbounded path expansion in __manifest endpointEPSS 0.5%CVE-2026-9137MEDIUMCSP Report Endpoint Log Flooding in MISP via Incorrect Size LimitEPSS 0.5%CVE-2026-54609HIGHQTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwardingEPSS 0.5%CVE-2026-27852HIGHAn attacker that can send mail to a user can craft a message whose headers contain a very large number of email addresses or MIME parametersEPSS 0.5%CVE-2026-14981HIGHIBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilitiesEPSS 0.5%CVE-2026-83281HIGHVulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver). Supported versions that are affected are 4EPSS 0.5%CVE-2026-46374HIGHSQLFluff: Uncontrolled Resource Consumption in ParserEPSS 0.5%CVE-2026-83276HIGHVulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webclient-http2). Supported versions that are affectedEPSS 0.5%CVE-2026-34404MEDIUMNuxt OG Image vulnerable to DoS via image generationEPSS 0.5%CVE-2026-46679HIGHlibp2p: Memory DoS via subscription flood of unique topicsEPSS 0.5%