Fallos del tipo CWE-400

3041 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2026-60186MEDIUMVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions EPSS 0.4%CVE-2026-60184MEDIUMVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affeEPSS 0.4%CVE-2026-60185MEDIUMVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affeEPSS 0.4%CVE-2026-27307LOWColdFusion | Uncontrolled Resource Consumption (CWE-400)EPSS 0.4%CVE-2026-60177MEDIUMVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Clone Plugin). Supported versions that are affEPSS 0.4%CVE-2025-50100LOWVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Thread Pooling). Supported versions that are affected are 8.0EPSS 0.4%CVE-2025-61301HIGHDenial-of-analysis in reporting/mongodb.py and reporting/jsondump.py in CAPEv2 (commit 52e4b43, on 2025-05-17) allows attackers who can submEPSS 0.4%CVE-2026-48187MEDIUMEmail with special content can lead to DoSEPSS 0.4%CVE-2021-32455MEDIUMSITEL CAP/PRX vulnerable to a denial of service attackEPSS 0.4%CVE-2026-60667HIGHVulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Core). The supported version that EPSS 0.4%CVE-2026-76693HIGHUnauthenticated Denial-of-Service Vulnerability in HPE Networking EdgeConnect SD-WAN GatewaysEPSS 0.4%CVE-2025-53893HIGHFile Browser Vulnerable to Uncontrolled Memory Consumption Due to Oversized File ProcessingEPSS 0.4%CVE-2026-53493MEDIUMContainerd has image-pull DoS via crafted OCI index graph amplificationEPSS 0.4%CVE-2025-52494HIGHAdacore Ada Web Server (AWS) before 25.2 is vulnerable to a denial-of-service (DoS) condition due to improper handling of SSL handshakes durEPSS 0.4%CVE-2026-83347MEDIUMVulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3. EasiEPSS 0.4%CVE-2026-19587MEDIUMUncontrolled Resource Consumption vulnerability in Samsung Open Source rlottie allows Excessive Allocation.EPSS 0.4%CVE-2025-57317HIGHapidoc-core is the core parser library to generate apidoc result following the apidoc-spec. A Prototype Pollution vulnerability in the prePrEPSS 0.4%CVE-2026-45149MEDIUMbrace-expansion: Large numeric range defeats documented `max` DoS protectionEPSS 0.4%CVE-2026-20084HIGHA vulnerability in the DHCP snooping feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause BOOTP packetsEPSS 0.4%CVE-2026-33444MEDIUMMemory management vulnerability in Secure Access serversEPSS 0.4%