Fallos del tipo CWE-400

3041 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2021-1563MEDIUMCisco Video Surveillance 7000 Series IP Cameras Cisco Discovery and Link Layer Discovery Protocol Memory Leak VulnerabilitiesEPSS 0.4%CVE-2026-60582HIGHVulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). The supported versioEPSS 0.4%CVE-2022-31030MEDIUMcontainerd CRI plugin: Host memory exhaustion through ExecSyncEPSS 0.4%CVE-2025-30753MEDIUMVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.4%CVE-2023-32611MEDIUMG_variant_byteswap() can take a long time with some non-normal inputsEPSS 0.4%CVE-2026-43870HIGHApache Thrift: Node.js web_server.js multi-vulnerabilityEPSS 0.4%CVE-2023-52098HIGHDenial of Service (DoS) vulnerability in the DMS module. Successful exploitation of this vulnerability will affect availability.EPSS 0.4%CVE-2023-52113HIGHlaunchAnyWhere vulnerability in the ActivityManagerService module. Successful exploitation of this vulnerability will affect availability.EPSS 0.4%CVE-2023-49555MEDIUMAn issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expand_smacro function in the modules/preprocsEPSS 0.4%CVE-2023-5522MEDIUMMobile app freezes when receiving a post with hundreds of emojisEPSS 0.4%CVE-2026-7528HIGHUnauthenticated File Upload Vulnerability Allows Disk Space Exhaustion and Path Disclosure in Langflow OSSEPSS 0.4%CVE-2025-66863HIGHAn issue was discovered in function d_discriminator in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service viaEPSS 0.4%CVE-2025-63561HIGHSummer Pearl Group Vacation Rental Management Platform prior to 1.0.2 is susceptible to a Slowloris-style Denial-of-Service (DoS) condition EPSS 0.4%CVE-2026-60647HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions tEPSS 0.4%CVE-2024-5652MEDIUMIn Docker Desktop on Windows before v4.31.0 allows a user in the docker-users group to cause a Windows Denial-of-Service through the exec-path Docker daemon config option in Windows containers modeEPSS 0.4%CVE-2026-33123MEDIUMpypdf has inefficient decoding of array-based streamsEPSS 0.4%CVE-2026-47214HIGHDocling: Unsafe URI and Path Handling in HTML BackendEPSS 0.4%CVE-2026-33443HIGHMemory management error in Secure Access servers prior to 14.55EPSS 0.4%CVE-2026-54260MEDIUMWagtail: Denial of service via unbounded filter specs in the image previewEPSS 0.4%CVE-2026-10224MEDIUMNousResearch hermes-agent Webhook Endpoint feishu.py _handle_webhook_request resource consumptionEPSS 0.4%