Fallos del tipo CWE-400

3041 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2021-22553MEDIUMHeap Memory exhaustion in GerritEPSS 0.4%CVE-2026-21950MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 9.0.0-9.EPSS 0.4%CVE-2026-21949MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 9.0.0-9.EPSS 0.4%CVE-2026-41711MEDIUMPotential Denial of Service through crafted Sort ParametersEPSS 0.4%CVE-2026-57204MEDIUMpypdf: Missing stream length values ignore defined limitsEPSS 0.4%CVE-2026-55399MEDIUMResource exhaustion vulnerability in the Secure Access publisherEPSS 0.4%CVE-2024-31399MEDIUMExcessive platform resource consumption within a loop issue exists in Cybozu Garoon 5.0.0 to 5.15.2. If this vulnerability is exploited, proEPSS 0.4%CVE-2026-54786LOWWasmtime: Leak in WASIp1 `fd_renumber` implementationEPSS 0.4%CVE-2026-13149HIGHbrace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number oEPSS 0.4%CVE-2026-16376HIGHDenial-of-service in the Graphics: WebGPU componentEPSS 0.4%CVE-2024-21658MEDIUMInsufficient control of region value length in discourse-calendarEPSS 0.4%CVE-2026-22540CRITICALDENIAL OF SERVICE VIA ARP PACKETSEPSS 0.4%CVE-2025-2811MEDIUMGL.iNet GL-A1300 Slate Plus API redosEPSS 0.4%CVE-2025-66019MEDIUMpypdf manipulated LZWDecode streams can exhaust RAMEPSS 0.4%CVE-2021-3759—A memory overflow vulnerability was found in the Linux kernel’s ipc functionality of the memcg subsystem, in the way a user calls the semgetEPSS 0.4%CVE-2026-21485HIGHiccDEV Undefined Behavior (UB) and Out of Memory in CIccProfile::LoadTag()EPSS 0.4%CVE-2026-60177MEDIUMVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Clone Plugin). Supported versions that are affEPSS 0.4%CVE-2026-47012MEDIUMVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affectEPSS 0.4%CVE-2026-60182MEDIUMVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Clone Plugin). Supported versions that are affEPSS 0.4%CVE-2026-60185MEDIUMVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affeEPSS 0.4%