Fallos del tipo CWE-400

3039 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2024-33618HIGHUncontrolled Resource Consumption in Bosch VMS Central Server in Bosch VMS 12.0.1 allows attackers to consume excessive amounts of disk spEPSS 0.5%CVE-2026-20066MEDIUMMultiple Cisco Products Snort 3 TBD Denial of Service VulnerabilityEPSS 0.5%CVE-2026-42343MEDIUMFastGPT: Uncontrolled Resource Consumption leading to Sandbox ExhaustionEPSS 0.5%CVE-2025-55558HIGHA buffer overflow occurs in pytorch v2.7.0 when a PyTorch model consists of torch.nn.Conv2d, torch.nn.functional.hardshrink, and torch.TensoEPSS 0.5%CVE-2025-11635MEDIUMTomofun Furbo 360 File Upload resource consumptionEPSS 0.5%CVE-2020-3543MEDIUMCisco Video Surveillance 8000 Series IP Cameras Cisco Discovery Protocol Memory Leak VulnerabilityEPSS 0.5%CVE-2025-30730HIGHVulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are afEPSS 0.5%CVE-2026-86421MEDIUMImageMagick before 7.1.2-30 Memory Leak via MSL decoderEPSS 0.5%CVE-2026-65976MEDIUMDeskflow: Clipboard receiver can accumulate data beyond Deskflow's configured clipboard size limitEPSS 0.5%CVE-2026-55531MEDIUMPraisonAI: Unauthenticated unbounded session accumulation in the PraisonAI MCP HTTP server (memory exhaustion; session TTL never enforced)EPSS 0.5%CVE-2026-45802MEDIUMFPDI: Memory Exhaustion and Endless Loop in FPDI leads to Denial of ServiceEPSS 0.5%CVE-2026-73215HIGHThe coturn server can end in a state where it does not accept more requests with "even-port" enabled.EPSS 0.5%CVE-2026-61144MEDIUMVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affectEPSS 0.4%CVE-2026-34304MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0EPSS 0.4%CVE-2026-91777HIGHjackson-databind: quadratic forward-reference completion in Collection and Map deserializersEPSS 0.4%CVE-2025-29484HIGHAn out-of-memory error in the parseABC_NS_SET_INFO function of libming v0.4.8 allows attackers to cause a Denial of Service (DoS) due to allEPSS 0.4%CVE-2026-91776HIGHjackson-databind: unbounded growth of the type id cache in TypeDeserializerBase retains every unknown raw type IDEPSS 0.4%CVE-2026-47008MEDIUMVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: InnoDB). Supported versions that are affected are MySQEPSS 0.4%CVE-2024-6501LOWNetworkmanager: denial of serviceEPSS 0.4%CVE-2026-47052MEDIUMVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: InnoDB). Supported versions that are affected are MySQEPSS 0.4%