Fallos del tipo CWE-400

3039 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2026-35034MEDIUMJellyfin: Potential Application DoS from excessively large SyncPlay group namesEPSS 0.4%CVE-2026-33541MEDIUMTSPortal's Uncontrolled User Creation via Validation Side Effects Leads to Potential Denial of ServiceEPSS 0.4%CVE-2024-5055HIGHVulnerability of uncontrolled resource consumption in XAMPPEPSS 0.4%CVE-2026-68904HIGHnode-opcua: TCP Socket Leak (FIN-WAIT-2) via keepalive reconnection cycle - Resource ExhaustionEPSS 0.4%CVE-2026-41721MEDIUMSpring Data Commons Denial of Service via Data BindingEPSS 0.4%CVE-2025-40944HIGHA vulnerability has been identified in SIMATIC ET 200AL IM 157-1 PN (6ES7157-1AB00-0AB0) (All versions), SIMATIC ET 200MP IM 155-5 PN HF (6EEPSS 0.4%CVE-2026-33625HIGHLMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant_dtype in model config loadingEPSS 0.4%CVE-2026-55247CRITICALplone.app.event: Denial of service via iCalendar importEPSS 0.4%CVE-2026-55248CRITICALplone.app.portlets: Denial of service via RSS feed portletEPSS 0.4%CVE-2024-44227HIGHThe issue was addressed with improved memory handling. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An app may be able to EPSS 0.4%CVE-2026-23940HIGHDenial of Service via Oversized Package UploadEPSS 0.4%CVE-2024-7708HIGHFor requests that have a body, but reading the body may end up in reading 0 bytes, there is a buffer leak. This is particularly the case forEPSS 0.4%CVE-2026-94408MEDIUMUncontrolled Resource Consumption in Elasticsearch Leading to denial of serviceEPSS 0.4%CVE-2026-22690LOWpypdf has possible long runtimes for missing /Root object with large /Size valuesEPSS 0.4%CVE-2026-3116MEDIUMImproper Input Validation in Zoom Plugin Webhook HandlerEPSS 0.4%CVE-2026-22691LOWpypdf has possible long runtimes for malformed startxrefEPSS 0.4%CVE-2026-22815MEDIUMAIOHTTP: Uncapped memory usage possible through aiohttp allowing unlimited trailer headersEPSS 0.4%CVE-2026-6416LOWTanium addressed an uncontrolled resource consumption vulnerability in Interact.EPSS 0.4%CVE-2025-49595MEDIUMn8n Vulnerable to Denial of Service via Malformed Binary Data RequestsEPSS 0.4%CVE-2026-30662MEDIUMConcreteCMS v9.4.7 contains a Denial of Service (DoS) vulnerability in the File Manager component. The 'download' method in 'concrete/controEPSS 0.4%