Fallos del tipo CWE-400

3039 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2025-46580HIGHZTE GoldenDB Database product has a code-related vulnerabilityEPSS 0.4%CVE-2022-4003LOWA denial-of-service vulnerability could allow an authenticated user to trigger an internal service restart via a specially crafted API requeEPSS 0.4%CVE-2025-9182HIGHDenial-of-service due to out-of-memory in the Graphics: WebRender componentEPSS 0.4%CVE-2024-11835HIGHDenial of ServiceEPSS 0.4%CVE-2025-41360HIGHUncontrolled resource consumption vulnerability in IDF and ZLFEPSS 0.4%CVE-2025-54575MEDIUMImageSharp Triggers an Infinite Loop in its GIF Decoder When Skipping Malformed Comment Extension BlocksEPSS 0.4%CVE-2026-61816HIGHzbateson/mail-mime-parser has uncontrolled resource consumption (CPU/memory DoS) parsing untrusted MIMEEPSS 0.4%CVE-2025-6208MEDIUMUncontrolled Memory Consumption in run-llama/llama_indexEPSS 0.4%CVE-2026-21948MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.EPSS 0.4%CVE-2026-61165HIGHVulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge). The supported version EPSS 0.4%CVE-2026-21941MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.EPSS 0.4%CVE-2026-29049MEDIUMmelange: unbounded HTTP download in `melange update-cache` can exhaust disk in CIEPSS 0.4%CVE-2026-21952MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 9.0.0-9.5.0EPSS 0.4%CVE-2025-25193MEDIUMDenial of Service attack on windows app using NettyEPSS 0.4%CVE-2025-9464HIGHRockwell Automation ArmorStart® LT - Multiple Denial-of-Service VulnerabilitiesEPSS 0.4%CVE-2026-47183MEDIUMZeroconf: Unbounded exception-dedup state retains packet buffers via traceback frame locals, enabling LAN-local memory exhaustionEPSS 0.4%CVE-2025-37161HIGHUnauthenticated Remote Denial-of-Service (DoS) Vulnerability in Web Management InterfaceEPSS 0.4%CVE-2026-10675MEDIUMBluetooth Mesh PB-ADV: invalidated provisioning link kept alive indefinitely, blocking (re)provisioning (DoS)EPSS 0.4%CVE-2026-25140HIGHapko affected by potential unbounded resource consumption in expandapk.ExpandApk on attacker-controlled .apk streamsEPSS 0.4%CVE-2023-32665MEDIUMGvariant deserialisation does not match spec for non-normal dataEPSS 0.4%