Fallos del tipo CWE-400

3039 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2026-30662MEDIUMConcreteCMS v9.4.7 contains a Denial of Service (DoS) vulnerability in the File Manager component. The 'download' method in 'concrete/controEPSS 0.4%CVE-2018-16878MEDIUMA flaw was found in pacemaker up to and including version 2.0.1. An insufficient verification inflicted preference of uncontrolled processesEPSS 0.4%CVE-2022-4986HIGHHirschmann EagleSDV Denial of Service via TLSEPSS 0.4%CVE-2024-57079HIGHA prototype pollution in the lib.deepMerge function of @zag-js/core v0.50.0 allows attackers to cause a Denial of Service (DoS) via supplyinEPSS 0.4%CVE-2024-44192MEDIUMThe issue was addressed with improved checks. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2,EPSS 0.4%CVE-2026-10069HIGHShibby Tomato miniupnpd resource consumptionEPSS 0.4%CVE-2023-45028MEDIUMQTS, QuTS hero, QuTScloudEPSS 0.4%CVE-2026-54338MEDIUMJupyterHub: Unauthenticated Denial of Service via Unbounded Username Logging on Failed LoginEPSS 0.4%CVE-2026-7493MEDIUMAppointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.11.5 - Unauthenticated Denial of ServiceEPSS 0.4%CVE-2026-91969HIGHvikunja before 2.6.0 Resource Exhaustion via CSV MigrationEPSS 0.4%CVE-2026-61617HIGHPterodactyl Wings SFTP write path does not enforce disk quota, allowing node-wide disk exhaustionEPSS 0.4%CVE-2026-57914MEDIUMApache Kerby: StackOverflow on parsing deeply nested ASN1 structuresEPSS 0.4%CVE-2026-90927HIGHfilebrowser through 2.63.23 Denial of Service via unbounded WebSocket messageEPSS 0.4%CVE-2024-54546HIGHThe issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15. An app may be able to cause unexpected systeEPSS 0.4%CVE-2026-91971HIGHVikunja before 2.6.0 Denial of Service via Avatar UploadEPSS 0.4%CVE-2026-91979HIGHVikunja before 2.6.0 Denial of Service via Decompression BombEPSS 0.4%CVE-2026-86255HIGHwger before 2.5 Uncontrolled Resource Consumption via date_sequenceEPSS 0.4%CVE-2026-86204HIGHPocketMine-MP before 5.39.2 Denial of Service via ModalFormResponsePacketEPSS 0.4%CVE-2026-48987MEDIUMpyLoad: Unbounded Memory Growth Leading to DoS and Potential DDoS in EventManagerEPSS 0.4%CVE-2026-62326MEDIUMWeblate Has Uncontrolled Resource Consumption viaEPSS 0.4%