Fallos del tipo CWE-400

3039 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2024-54546HIGHThe issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15. An app may be able to cause unexpected systeEPSS 0.4%CVE-2026-28967MEDIUMA denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPEPSS 0.4%CVE-2024-42651HIGHNanoMQ v0.17.9 was discovered to contain a heap use-after-free vulnerability via the component sub_Ctx_handle. This vulnerability allows attEPSS 0.4%CVE-2024-43105MEDIUMExcessive Resource Consumption via `/export`EPSS 0.4%CVE-2026-83457HIGHVulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations). Supported versionEPSS 0.4%CVE-2025-60790MEDIUMProcessWire CMS 3.0.246 allows a low-privileged user with lang-edit to upload a crafted ZIP to Language Support that is auto-extracted withoEPSS 0.4%CVE-2022-23951MEDIUMIn Keylime before 6.3.0, quote responses from the agent can contain possibly untrusted ZIP data which can lead to zip bombs.EPSS 0.4%CVE-2026-43804MEDIUMThis issue was addressed through improved state management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, EPSS 0.4%CVE-2025-54604HIGHBitcoin Core through 29.0 allows Uncontrolled Resource Consumption (issue 1 of 2).EPSS 0.4%CVE-2024-42399MEDIUMUnauthenticated Denial-of-Service (DoS) Vulnerabilities in the Soft AP Daemon Service Accessed by the PAPI ProtocolEPSS 0.4%CVE-2021-44320HIGHParrot AR.Drone version 1 and 2 does not employ a suitable mechanism to prevent denial-of-service (DoS) attacks. An attacker can harm the deEPSS 0.4%CVE-2026-47706MEDIUMStrawberry GraphQL has a Circular Fragment Reference DOSEPSS 0.4%CVE-2026-42127HIGHPre-authentication denial of service in the public dashboard query endpointEPSS 0.4%CVE-2026-41146HIGHfacil.io and downstream iodine ruby gem vulnerable to uncontrolled resource consumption and loop with unreachable exit conditionEPSS 0.4%CVE-2025-27097MEDIUMCache variables with the operations when transforms exist on the root level even if variables change in the further requests with the same operationEPSS 0.4%CVE-2025-54605HIGHBitcoin Core through 29.0 allows Uncontrolled Resource Consumption (issue 2 of 2).EPSS 0.4%CVE-2023-49557MEDIUMAn issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the yasm_section_bcs_first function in the libyasmEPSS 0.4%CVE-2024-42398MEDIUMUnauthenticated Denial-of-Service (DoS) Vulnerabilities in the Soft AP Daemon Service Accessed by the PAPI ProtocolEPSS 0.4%CVE-2026-48988MEDIUMmarkdown-it: Quadratic complexity DoS in smartquotes rule via replaceAt string operationsEPSS 0.4%CVE-2025-48040MEDIUMMalicious Key Exchange Messages may Lead to Excessive Resource ConsumptionEPSS 0.4%