Fallos del tipo CWE-400

3039 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2025-59472MEDIUMA denial of service vulnerability exists in Next.js versions with Partial Prerendering (PPR) enabled when running in minimal mode. The PPR rEPSS 0.4%CVE-2025-44651HIGHIn TRENDnet TPL-430AP FW1.0, the USERLIMIT_GLOBAL option is set to 0 in the bftpd-related configuration file. This can cause DoS attacks wheEPSS 0.4%CVE-2025-44653HIGHIn H3C GR2200 MiniGR1A0V100R016, the USERLIMIT_GLOBAL option is set to 0 in the /etc/bftpd.conf. This can cause DoS attacks when unlimited uEPSS 0.4%CVE-2025-66960HIGHAn issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the fs/ggml/gguf.go, function readGGUFV1String reads EPSS 0.4%CVE-2022-47696—An issue was discovered Binutils objdump before 2.39.3 allows attackers to cause a denial of service or other unspecified impacts via functiEPSS 0.4%CVE-2026-48525MEDIUMPyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload segment in b64=false detached JWSEPSS 0.4%CVE-2025-52867MEDIUMQsync CentralEPSS 0.4%CVE-2022-43893LOWIBM Security Verify Privilege denial of serviceEPSS 0.4%CVE-2026-61186CRITICALVulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version tEPSS 0.4%CVE-2024-35194MEDIUMStacklok Minder vulnerable to denial of service from maliciously crafted templatesEPSS 0.4%CVE-2024-41434MEDIUMPingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component (*Column).GetDecimal. This allows attackers to cause a DenEPSS 0.4%CVE-2024-37281MEDIUMKibana Denial of Service issueEPSS 0.4%CVE-2020-1678MEDIUMJunos OS and Junos OS Evolved: RPD can crash due to a slow memory leak.EPSS 0.4%CVE-2025-27421HIGHGoroutine Leak in Abacus SSE ImplementationEPSS 0.4%CVE-2025-59975HIGHJunos Space: Flooding device with inbound API calls leads to WebUI and CLI management access DoSEPSS 0.4%CVE-2026-76000MEDIUMColdFusion | Uncontrolled Resource Consumption (CWE-400)EPSS 0.4%CVE-2026-49343MEDIUMKlever-Go KVM: Throttler slot leak in trie account-data sync causes epoch bootstrap / state sync DoSEPSS 0.4%CVE-2024-33001MEDIUMDenial of service (DOS) in SAP NetWeaver and ABAP platformEPSS 0.4%CVE-2025-5890MEDIUMactions toolkit glob internal-pattern.ts globEscape redosEPSS 0.4%CVE-2026-56725HIGHZammad: Denial of Service via OTRS Import ControllerEPSS 0.4%