Fallos del tipo CWE-400

3039 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2026-88798MEDIUMReally Simple Security (Free) < 9.8.3 - Unauthenticated Unbounded Option Growth via Spoofed Client IP HeaderEPSS 0.4%CVE-2026-35441MEDIUMDirectus Affected by GraphQL Alias Amplification Denial-of-Service Due to Missing Query Cost/Complexity LimitsEPSS 0.4%CVE-2026-40980MEDIUMIn Spring AI, a malicious PDF file can be crafted that triggers the allocation of unreasonable amounts of memory when handled by `ForkPDFLayEPSS 0.4%CVE-2026-27879MEDIUMQuery resampling can cause unbounded memory allocationsEPSS 0.4%CVE-2026-63136MEDIUMUncontrolled Resource Consumption in Elasticsearch Leading to Denial of ServiceEPSS 0.4%CVE-2026-73728MEDIUMAuthenticated Denial of Service Vulnerabilities in HPE Networking Fabric Composer APIEPSS 0.4%CVE-2026-49090MEDIUMUncontrolled Resource Consumption in Elasticsearch Leading to Denial of ServiceEPSS 0.4%CVE-2020-8299—Citrix ADC and Citrix/NetScaler Gateway 13.0 before 13.0-76.29, 12.1-61.18, 11.1-65.20, Citrix ADC 12.1-FIPS before 12.1-55.238, and Citrix EPSS 0.4%CVE-2026-44019HIGHDocling Core has insufficient validation of image reference URIsEPSS 0.4%CVE-2026-40347MEDIUMPython-Multipart affected by Denial of Service via large multipart preamble or epilogue dataEPSS 0.4%CVE-2024-5052HIGHResource consumption vulnerability in Cerberus FTP EnterpriseEPSS 0.4%CVE-2022-1325—A flaw was found in Clmg, where with the help of a maliciously crafted pandore or bmp file with modified dx and dy header field values it isEPSS 0.4%CVE-2023-30311HIGHAn issue discovered in H3C Magic R365 and H3C Magic R100 routers allows attackers to hijack TCP sessions which could lead to a denial of serEPSS 0.4%CVE-2024-37125HIGHDell SmartFabric OS10 Software, versions 10.5.6.x, 10.5.5.x, 10.5.4.x,10.5.3.x, contains an Uncontrolled Resource Consumption vulnerability.EPSS 0.4%CVE-2025-59472MEDIUMA denial of service vulnerability exists in Next.js versions with Partial Prerendering (PPR) enabled when running in minimal mode. The PPR rEPSS 0.4%CVE-2026-65347MEDIUMThe issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27,EPSS 0.4%CVE-2024-36743HIGHAn issue in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) when an empty array is processed with oneflow.doEPSS 0.4%CVE-2022-51018HIGHPocketMine-MP before 3.26.5 and 4.0.5 Input Validation via Book PagesEPSS 0.4%CVE-2025-70069HIGHAn issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXConverter.cpp and ConvertMeshMultiMaterial() metEPSS 0.4%CVE-2026-24484MEDIUMImageMagick: Converting multi-layer nested MVG to SVG can cause DoSEPSS 0.4%