Fallos del tipo CWE-400

3043 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2026-10291MEDIUMEnderfga claw-orchestrator Session Grep Endpoint embedded-server.ts validateRegex redosEPSS 0.4%CVE-2026-33444MEDIUMMemory management vulnerability in Secure Access serversEPSS 0.4%CVE-2026-55398MEDIUMMemory management vulnerability in Secure Access clientsEPSS 0.4%CVE-2026-20084HIGHA vulnerability in the DHCP snooping feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause BOOTP packetsEPSS 0.4%CVE-2026-67415MEDIUMRabbitMQ: Shovel Management Atom Exhaustion Allows Persistent Broker-Wide Denial of ServiceEPSS 0.4%CVE-2026-67226MEDIUMRabbitMQ: Admin-only atom exhaustion: PUT /api/users tags listEPSS 0.4%CVE-2026-42395MEDIUMA host listed as a trusted proxy can send forwarding information containing a NUL byte, which crashes the login process on the following logEPSS 0.4%CVE-2023-3614MEDIUMDenial of Service via specially crafted gif imageEPSS 0.4%CVE-2025-71000HIGHAn issue in the flow.cuda.BoolTensor component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted input.EPSS 0.4%CVE-2026-102278HIGHbrace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustionEPSS 0.4%CVE-2026-102276HIGHbrace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustionEPSS 0.4%CVE-2026-26066MEDIUMImageMagick has infinite loop when writing IPTCTEXT leads to denial of service via crafted profileEPSS 0.4%CVE-2024-12579MEDIUMMinify HTML <= 2.1.10 - - Regular Expressions Denial of ServiceEPSS 0.3%CVE-2024-57724MEDIUMlunasvg v3.0.0 was discovered to contain a segmentation violation via the component gray_record_cell.EPSS 0.3%CVE-2025-51741HIGHAn issue was discovered in Veal98 Echo Open-Source Community System 2.2 thru 2.3 allowing an unauthenticated attacker to cause the server toEPSS 0.3%CVE-2024-48077HIGHNanoMQ v0.22.7 is vulnerable to Denial of Service (DoS) due to improper resource throttling. A crafted sequence of requests causes the recv-EPSS 0.3%CVE-2026-100572MEDIUMOpenClaw before 2026.8.1 Denial of Service via Rate LimitEPSS 0.3%CVE-2026-100527MEDIUMOpenClaw before 2026.8.2 Denial of Service via Browser RelayEPSS 0.3%CVE-2026-100571MEDIUMOpenClaw before 2026.8.1 SMS Webhook Rate Limit BypassEPSS 0.3%CVE-2026-16837HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.3%