Fallos del tipo CWE-400

3039 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2026-33445HIGHMemory management vulnerability in Secure Access serversEPSS 0.4%CVE-2025-55102HIGHA denial-of-service vulnerability exists in the NetX IPv6 component functionality of Eclipse ThreadX NetX Duo. A specially crafted network pEPSS 0.4%CVE-2021-0257MEDIUMJunos OS: MX Series, EX9200 Series: Trio-based MPCs memory leak in VPLS with integrated routing and bridging (IRB) interfaceEPSS 0.4%CVE-2025-54572MEDIUMRuby SAML DOS vulnerability with large SAML responseEPSS 0.4%CVE-2025-56264HIGHThe /api/comment endpoint in zhangyd-c OneBlog 2.3.9 contains a denial-of-service vulnerability.EPSS 0.4%CVE-2026-28412MEDIUMTextream Vulnerable to Uncontrolled Resource Consumption (Denial of Service)EPSS 0.4%CVE-2026-60846MEDIUMVulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versioEPSS 0.4%CVE-2025-67731HIGHServify Express does not enforce rate limiting when parsing JSONEPSS 0.4%CVE-2026-27859MEDIUMA mail message containing excessive amount of RFC 2231 MIME parameters causes LMTP to use too much CPU. A suitably formatted mail message caEPSS 0.4%CVE-2023-50121MEDIUMAutel EVO NANO drone flight control firmware version 1.6.5 is vulnerable to denial of service (DoS).EPSS 0.4%CVE-2025-67835MEDIUMPaessler PRTG Network Monitor before 25.4.114 allows Denial-of-Service (DoS) by an authenticated attacker via the Notification Contacts funcEPSS 0.4%CVE-2022-2962HIGHA DMA reentrancy issue was found in the Tulip device emulation in QEMU. When Tulip reads or writes to the rx/tx descriptor or copies the rx/EPSS 0.4%CVE-2026-59315MEDIUMSpring Cloud Config Monitor Denial of ServiceEPSS 0.4%CVE-2026-101906HIGHAxios: ReDoS (O(N²)) in shouldBypassProxy host normalization, reachable via untrusted redirect LocationEPSS 0.4%CVE-2026-19113MEDIUMUnauthenticated denial of service via unbounded request body processingEPSS 0.4%CVE-2026-53596MEDIUMFreeScout has unrestricted file upload without rate limiting that leads to resource exhaustion (DoS)EPSS 0.4%CVE-2026-51106CRITICALAn issue in TokTok qTox v1.18.4 allows a local attacker to cause a denial of service via the src/persistence/serialize.cpp componentEPSS 0.4%CVE-2026-19475MEDIUMSQL Data Source Plugin: OOM DoS via $__timeGroup macroEPSS 0.4%CVE-2025-71418MEDIUMPocketMine-MP before 5.25.2 Denial of Service via explodeEPSS 0.4%CVE-2024-57085HIGHA prototype pollution in the function deepMerge of @stryker-mutator/util v8.6.0 allows attackers to cause a Denial of Service (DoS) via suppEPSS 0.4%