Fallos del tipo CWE-400

3039 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2026-33382HIGHDenial of service via unbounded request body sizeEPSS 0.4%CVE-2025-55152MEDIUMoak: ReDoS in x-forwarded-proto and x-forwarded-for headersEPSS 0.4%CVE-2026-60719CRITICALVulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Supported versions that are affected areEPSS 0.4%CVE-2025-66303MEDIUMGrav is vulnerable to a DOS on the admin panelEPSS 0.4%CVE-2023-45150MEDIUMInviting excessive long email addresses to a calendar event makes the Nextcloud server unresponsiveEPSS 0.4%CVE-2025-62260HIGHLiferay Portal 7.4.0 through 7.4.3.99, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and EPSS 0.4%CVE-2025-50057MEDIUMExtension - rsjoomla.com - DOS vulnerability RSFiles! component 1.16.3-1.17.7 for JoomlaEPSS 0.4%CVE-2023-1981MEDIUMA vulnerability was found in the avahi library. This flaw allows an unprivileged user to make a dbus call, causing the avahi daemon to crashEPSS 0.4%CVE-2026-93590MEDIUMImageMagick before 7.1.2-31 Policy Bypass in UHDR encoderEPSS 0.4%CVE-2025-11681HIGHDenial of Service condition in M-Files ServerEPSS 0.4%CVE-2025-48038MEDIUMUnverified File Handles can Cause Excessive Use of System ResourcesEPSS 0.4%CVE-2025-48041HIGHSSH_FXP_OPENDIR may Lead to Exhaustion of File HandlesEPSS 0.4%CVE-2025-48039MEDIUMUnverified Paths can Cause Excessive Use of System ResourcesEPSS 0.4%CVE-2026-101901HIGHAxios: Denial of Service via Unhandled 'error' Event in HTTP/2 ClientHttp2Session InitializationEPSS 0.4%CVE-2025-32436HIGHAutoGPT has a DoS vulnerability in AddAudioToVideoBlockEPSS 0.4%CVE-2021-0292MEDIUMJunos OS Evolved: Memory leak in arpd or ndp processes can lead to Denial of Service (DoS)EPSS 0.4%CVE-2021-1564MEDIUMCisco Video Surveillance 7000 Series IP Cameras Cisco Discovery and Link Layer Discovery Protocol Memory Leak VulnerabilitiesEPSS 0.4%CVE-2026-40019MEDIUMAn unauthenticated attacker can send a truncated quoted argument to the ManageSieve login process, which makes it spin in an infinite loop cEPSS 0.4%CVE-2026-60582HIGHVulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). The supported versioEPSS 0.4%CVE-2025-6297HIGHdpkg-deb: Fix cleanup for control member with restricted directoriesEPSS 0.4%