Fallos del tipo CWE-400

3039 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2026-91776HIGHjackson-databind: unbounded growth of the type id cache in TypeDeserializerBase retains every unknown raw type IDEPSS 0.4%CVE-2026-34304MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0EPSS 0.4%CVE-2026-61144MEDIUMVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affectEPSS 0.4%CVE-2026-34293MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.0-8.0.45. EPSS 0.4%CVE-2026-91777HIGHjackson-databind: quadratic forward-reference completion in Collection and Map deserializersEPSS 0.4%CVE-2026-33605HIGHAn unauthenticated attacker can crash the ManageSieve login process by sending a small malformed command before authenticating. If running iEPSS 0.4%CVE-2026-60208CRITICALVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.4%CVE-2025-53481HIGHDenial of service vector on ipinfo/v0/norevisionEPSS 0.4%CVE-2026-42391HIGHAn unauthenticated attacker can send an IMAP ID command with a very large number of parameters before logging in, which causes memory and CPEPSS 0.4%CVE-2024-7610MEDIUMUncontrolled Resource Consumption in GitLabEPSS 0.4%CVE-2025-57614HIGHAn issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) Integer overflow and invalid input vulnerability in the cached method allEPSS 0.4%CVE-2026-63448MEDIUMSuricata smb: some SMB flows can cause resource exhaustionEPSS 0.4%CVE-2025-50098LOWVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.EPSS 0.4%CVE-2026-17639MEDIUMCertain HP Smart Tank All in One – Potential Denial of ServiceEPSS 0.4%CVE-2024-2446MEDIUMMattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to limit the number of @-mentioEPSS 0.4%CVE-2022-47695—An issue was discovered Binutils objdump before 2.39.3 allows attackers to cause a denial of service or other unspecified impacts via functiEPSS 0.4%CVE-2025-27100MEDIUMAn authenticated user can crash lakeFS by exhausting server memoryEPSS 0.4%CVE-2025-59439HIGHAn issue was discovered in Samsung Mobile Processor, Wearable Processor and Modem Exynos 980, 990, 850, 1080, 9110, W920, W930, W1000 and MoEPSS 0.4%CVE-2026-35034MEDIUMJellyfin: Potential Application DoS from excessively large SyncPlay group namesEPSS 0.4%CVE-2026-5308MEDIUMMissing request body size limits on Zoom plugin HTTP endpointsEPSS 0.4%