Fallos del tipo CWE-400

3041 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2026-10224MEDIUMNousResearch hermes-agent Webhook Endpoint feishu.py _handle_webhook_request resource consumptionEPSS 0.4%CVE-2025-0426MEDIUMA security issue was discovered in Kubernetes where a large number of container checkpoint requests made to the unauthenticated kubelet readEPSS 0.4%CVE-2025-54884HIGHVision UI security-kit.js: Potential Uncontrolled Resource Allocation VulnerabilityEPSS 0.4%CVE-2026-20080MEDIUMCisco IEC6400 Edge Compute Appliance SSH Denial of Service VulnerabilityEPSS 0.4%CVE-2025-43796HIGHLiferay Portal 7.4.0 through 7.4.3.101, and Liferay DXP 2023.Q3.0 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA though update 35 doEPSS 0.4%CVE-2025-48053HIGHDiscourse vulnerable to DoS via large URL payload in PM to a botEPSS 0.4%CVE-2026-22542CRITICALDENIAL OF SERVICE FOR CONCURRENT CONNECTIONS ON TELNETEPSS 0.4%CVE-2023-38043HIGHA vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attackerEPSS 0.4%CVE-2022-27640—A vulnerability has been identified in SIMATIC CP 442-1 RNA (All versions < V1.5.18), SIMATIC CP 443-1 RNA (All versions < V1.5.18). The affEPSS 0.4%CVE-2026-60233MEDIUMVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 15.EPSS 0.4%CVE-2022-22155MEDIUMJunos OS: ACX5448: FPC memory leak due to IPv6 neighbor flapsEPSS 0.4%CVE-2026-60410MEDIUMVulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The suppoEPSS 0.4%CVE-2026-60303MEDIUMVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.EPSS 0.4%CVE-2026-33754MEDIUMWazuh: Unauthenticated cluster packet length leads to uncontrolled memory allocation (remote DoS)EPSS 0.4%CVE-2021-44527—A vulnerability found in UniFi Switch firmware Version 5.43.35 and earlier allows a malicious actor who has already gained access to the netEPSS 0.4%CVE-2026-83416MEDIUMVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.EPSS 0.4%CVE-2026-81725MEDIUMNLTK before 3.10.3 Regular Expression Denial of Service via Pl196xCorpusReaderEPSS 0.4%CVE-2026-58042MEDIUMA flaw in Node.js can cause dns.resolveAny() Aborts the Node.js Process When a DNS Response Contains More Than 256 A Records. Repeated trEPSS 0.4%CVE-2026-21949MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 9.0.0-9.EPSS 0.4%CVE-2026-60411MEDIUMVulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: ttcserver). The supported versiEPSS 0.4%