Fallos del tipo CWE-400

3039 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2026-34404MEDIUMNuxt OG Image vulnerable to DoS via image generationEPSS 0.5%CVE-2025-29898MEDIUMQsync CentralEPSS 0.5%CVE-2021-4467HIGHPositive Technologies MaxPatrol 8 & XSpider Remote DoSEPSS 0.5%CVE-2026-42467HIGHAn issue was discovered in Open-SAE-J1939 thru commit b6caf884df46435e539b1ecbf92b6c29b345bdfe (2025-11-30) in SAE_J1939_Read_Binary_Data_TrEPSS 0.5%CVE-2022-48716HIGHASoC: codecs: wcd938x: fix incorrect used of portidEPSS 0.5%CVE-2025-55197MEDIUMpypdf's Manipulated FlateDecode streams can exhaust RAMEPSS 0.5%CVE-2025-44531HIGHAn issue in Realtek RTL8762EKF-EVB RTL8762E SDK v1.4.0 allows attackers to cause a Denial of Service (DoS) via sending a crafted before a paEPSS 0.5%CVE-2025-62706MEDIUMAuthlib : JWE zip=DEF decompression bomb enables DoSEPSS 0.5%CVE-2025-70886HIGHAn issue in halo v.2.22.4 and before allows a remote attacker to cause a denial of service via a crafted payload to the public comment submiEPSS 0.5%CVE-2026-24485HIGHImageMagick: Infinite loop vulnerability when parsing a PCD fileEPSS 0.5%CVE-2019-15264HIGHCisco Aironet Access Points and Catalyst 9100 Access Points CAPWAP Denial of Service VulnerabilityEPSS 0.5%CVE-2024-47239MEDIUMDell PowerScale OneFS versions 8.2.2.x through 9.9.0.0 contain an uncontrolled resource consumption vulnerability. A remote low privileged aEPSS 0.5%CVE-2024-22164MEDIUMDenial of Service of an Investigation in Splunk Enterprise Security through Investigation attachmentsEPSS 0.5%CVE-2022-32505HIGHAn issue was discovered on certain Nuki Home Solutions devices. It is possible to send multiple BLE malformed packets to block some of the fEPSS 0.5%CVE-2026-35406MEDIUMAardvark-dns has incorrect error handling for malformed tcp packetsEPSS 0.5%CVE-2024-39810MEDIUMServer crash via Elasticsearch certificate fileEPSS 0.5%CVE-2026-76700MEDIUMUnauthenticated Denial-of-Service Vulnerabilities in HPE Networking EdgeConnect SD-WAN GatewaysEPSS 0.5%CVE-2024-33618HIGHUncontrolled Resource Consumption in Bosch VMS Central Server in Bosch VMS 12.0.1 allows attackers to consume excessive amounts of disk spEPSS 0.5%CVE-2026-6797MEDIUMSanluan PublicCMS DocToHtmlUtils.java ZipSecureFile.setMinflateRatio resource consumptionEPSS 0.5%CVE-2025-61303CRITICALHatching Triage Sandbox Windows 10 build 2004 (2025-08-14) and Windows 10 LTSC 2021(2025-08-14) contains a vulnerability in its Windows behaEPSS 0.5%