Fallos del tipo CWE-400

3039 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2026-54609HIGHQTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwardingEPSS 0.5%CVE-2026-27852HIGHAn attacker that can send mail to a user can craft a message whose headers contain a very large number of email addresses or MIME parametersEPSS 0.5%CVE-2026-14981HIGHIBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilitiesEPSS 0.5%CVE-2026-83349HIGHVulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.EPSS 0.5%CVE-2026-83333HIGHVulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3. EasiEPSS 0.5%CVE-2026-42342HIGHReact Router vulnerable to DoS via unbounded path expansion in __manifest endpointEPSS 0.5%CVE-2026-9137MEDIUMCSP Report Endpoint Log Flooding in MISP via Incorrect Size LimitEPSS 0.5%CVE-2026-83350HIGHVulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are 21.3-21.23 and 23.4EPSS 0.5%CVE-2026-83276HIGHVulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webclient-http2). Supported versions that are affectedEPSS 0.5%CVE-2024-37904MEDIUMDenial of service from maliciously configured Git repository in MinderEPSS 0.5%CVE-2026-41708HIGHSpring Cloud Sleuth instrumentation of Spring TX DoS vulnerabilityEPSS 0.5%CVE-2026-83330HIGHVulnerability in the Helidon product of Oracle Fusion Middleware (component: WebSocket). Supported versions that are affected are 4.0.0-4.5EPSS 0.5%CVE-2026-54712MEDIUMOpenTelemetry Javaagent RMI context propagation allows resource exhaustionEPSS 0.5%CVE-2026-41695HIGHDenial of Service in Spring Data Commons Property Path ResolutionEPSS 0.5%CVE-2026-40988HIGHUnbounded DEFLATE Inflation in SAML 2.0 Service ProviderEPSS 0.5%CVE-2026-75371HIGHAn integer handling flaw in the cobs_decode function of SpaceDot AcubeSAT OBC software commit eaf90ec allows physically-proximate attackers EPSS 0.5%CVE-2026-50879HIGHAn issue in the uploadPostHandler component of Andrei Marcu linx-server v2.3.8 allows attackers to cause a Denial of Service (DoS) via a craEPSS 0.5%CVE-2026-70906HIGHVulnerability in Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 25.0.4 and 26.0.2. Easily exploiEPSS 0.5%CVE-2026-41842HIGHSpring Framework Denial of Service via Versioned Resources in Spring MVC and WebFluxEPSS 0.5%CVE-2026-73773HIGHUnauthenticated Denial-of-Service (DoS) Vulnerability in AOS-CXEPSS 0.5%