Fallos del tipo CWE-400

3039 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2026-61194MEDIUMVulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Core). The supported version thatEPSS 0.4%CVE-2026-60311MEDIUMVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affectEPSS 0.4%CVE-2026-60399MEDIUMVulnerability in Oracle GoldenGate (component: Receiver Service Executable). Supported versions that are affected are 19.1.0.0.0-19.30.0.0,EPSS 0.4%CVE-2025-65888HIGHA dimension validation flaw in the flow.empty() component of OneFlow 0.9.0 allows attackers to cause a Denial of Service (DoS) via a negativEPSS 0.4%CVE-2026-34271MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affectEPSS 0.4%CVE-2026-61109MEDIUMVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: JSON). Supported versions that are affected arEPSS 0.4%CVE-2026-61195MEDIUMVulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Core). The supported version thatEPSS 0.4%CVE-2025-25341HIGHA vulnerability exists in the libxmljs 1.0.11 when parsing a specially crafted XML document. Accessing the internal _ref property on entity_EPSS 0.4%CVE-2025-65886HIGHA shape mismatch vulnerability in OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via supplying crafted tensor shapes.EPSS 0.4%CVE-2025-70999HIGHA GPU device-ID validation flaw in the flow.cuda.get_device_capability() component of OneFlow v0.9.0 allows attackers to cause a Denial of SEPSS 0.4%CVE-2026-60324MEDIUMVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affectEPSS 0.4%CVE-2026-61108MEDIUMVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: GIS). Supported versions that are affected areEPSS 0.4%CVE-2026-34276MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affectEPSS 0.4%CVE-2026-34308MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: JSON). Supported versions that are affected are 8.0.0-8.0.45,EPSS 0.4%CVE-2026-5755MEDIUMDenial of service via crafted TIFF file uploadEPSS 0.4%CVE-2026-40980MEDIUMIn Spring AI, a malicious PDF file can be crafted that triggers the allocation of unreasonable amounts of memory when handled by `ForkPDFLayEPSS 0.4%CVE-2026-33378MEDIUMGrafana Data Source Plugin: DoS (OOM) via Negative Interval Injection in $__timeGroup MacroEPSS 0.4%CVE-2026-73728MEDIUMAuthenticated Denial of Service Vulnerabilities in HPE Networking Fabric Composer APIEPSS 0.4%CVE-2026-9602MEDIUMMattermost Desktop App crashes when malformed arguments are provided to some exposed IPC methodsEPSS 0.4%CVE-2026-61160HIGHVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience MaEPSS 0.4%