Fallos del tipo CWE-400

3039 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2026-61070MEDIUMVulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Cash Management). The supEPSS 0.4%CVE-2026-36724MEDIUMAn uncaught exception in the /application/job/update/{id} endpoint of FastapiAdmin v2.2.0 allows authenticated attackers with the module_tasEPSS 0.4%CVE-2025-44528HIGHAn issue in Texas Instruments LP-CC2652RB SimpleLink CC13XX CC26XX SDK 7.41.00.17 allows attackers to cause a Denial of Service (DoS) via seEPSS 0.4%CVE-2025-50103MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: LDAP Auth). Supported versions that are affected arEPSS 0.4%CVE-2024-47212HIGHAn issue was discovered in Iglu Server 0.13.0 and below. It involves sending very large payloads to a particular API endpoint of Iglu ServerEPSS 0.4%CVE-2026-46866HIGHVulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen). Supported veEPSS 0.4%CVE-2024-56528HIGHThis vulnerability affects Snowplow Collector 3.x before 3.3.0 (unless it’s set up behind a reverse proxy that establishes payload limits). EPSS 0.4%CVE-2026-47046HIGHVulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Easily exploitableEPSS 0.4%CVE-2026-57224MEDIUMSuricata dhcp: unbounded transactions in unidirectional traffic can lead to resource exhaustionEPSS 0.4%CVE-2025-21087HIGHTMM VulnerabilityEPSS 0.4%CVE-2024-47535MEDIUMDenial of Service attack on windows app using NettyEPSS 0.4%CVE-2025-20058HIGHBIG-IP message routing vulnerabilityEPSS 0.4%CVE-2024-29153HIGHA vulnerability was discovered in Samsung Mobile Processor, Wearable Processor, and Modems with versions Exynos 9820, Exynos 9825, Exynos 98EPSS 0.4%CVE-2024-24943MEDIUMIn JetBrains Toolbox App before 2.2 a DoS attack was possible via a malicious SVG imageEPSS 0.4%CVE-2023-1071LOWAn issue has been discovered in GitLab affecting all versions from 15.5 before 15.8.5, all versions starting from 15.9 before 15.9.4, all veEPSS 0.4%CVE-2022-40513HIGHUncontrolled resource consumption in WLAN Firmware.EPSS 0.4%CVE-2024-24975LOW Denial of Service for mobile app users due to automatic code highlightingEPSS 0.4%CVE-2023-21339HIGHIn Minikin, there is a possible way to trigger ANR by showing a malicious message due to resource exhaustion. This could lead to remote deniEPSS 0.4%CVE-2025-55102HIGHA denial-of-service vulnerability exists in the NetX IPv6 component functionality of Eclipse ThreadX NetX Duo. A specially crafted network pEPSS 0.4%CVE-2026-33445HIGHMemory management vulnerability in Secure Access serversEPSS 0.4%