Fallos del tipo CWE-400

2985 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2018-15383—Cisco Adaptive Security Appliance Direct Memory Access Denial of Service VulnerabilityEPSS 2.5%CVE-2022-24729MEDIUMRegular expression Denial of Service in dialog pluginEPSS 2.5%CVE-2020-7587—A vulnerability has been identified in Opcenter Execution Discrete (All versions < V3.2), Opcenter Execution Foundation (All versions < V3.2EPSS 2.5%CVE-2026-23864HIGHMultiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-server-dom-parcel, reacEPSS 2.5%CVE-2026-45591HIGHASP.NET Core Denial of Service VulnerabilityEPSS 2.5%CVE-2025-27469HIGHWindows Lightweight Directory Access Protocol (LDAP) Denial of Service VulnerabilityEPSS 2.5%CVE-2019-1873HIGHCisco ASA and FTD Software Cryptographic TLS and SSL Driver Denial of Service VulnerabilityEPSS 2.5%CVE-2021-21306MEDIUMDenial of Service in MarkedEPSS 2.5%CVE-2020-8220—A denial of service vulnerability exists in Pulse Connect Secure <9.1R8 that allows an authenticated attacker to perform command injection vEPSS 2.5%CVE-2023-34462MEDIUMnetty-handler SniHandler 16MB allocationEPSS 2.5%CVE-2016-10523—MQTT before 3.4.6 and 4.0.x before 4.0.5 allows specifically crafted MQTT packets to crash the application, making a DoS attack feasible witEPSS 2.5%CVE-2022-24863HIGHDenial of service in http-swaggerEPSS 2.4%CVE-2023-36703HIGHDHCP Server Service Denial of Service VulnerabilityEPSS 2.4%CVE-2019-6559—Moxa IKS and EDS allow remote authenticated users to cause a denial of service via a specially crafted packet, which may cause the switch toEPSS 2.4%CVE-2020-1700MEDIUMA flaw was found in the way the Ceph RGW Beast front-end handles unexpected disconnects. An authenticated attacker can abuse this flaw by maEPSS 2.4%CVE-2024-38015HIGHWindows Remote Desktop Gateway (RD Gateway) Denial of Service VulnerabilityEPSS 2.4%CVE-2024-21386HIGH.NET Denial of Service VulnerabilityEPSS 2.4%CVE-2018-0230—A vulnerability in the internal packet-processing functionality of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 SeEPSS 2.4%CVE-2025-21270HIGHMicrosoft Message Queuing (MSMQ) Denial of Service VulnerabilityEPSS 2.4%CVE-2023-36579HIGHMicrosoft Message Queuing (MSMQ) Denial of Service VulnerabilityEPSS 2.4%