Fallos del tipo CWE-400

3051 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2025-67445MEDIUMTOTOLINK X5000R V9.1.0cu.2415_B20250515 contains a denial-of-service vulnerability in /cgi-bin/cstecgi.cgi. The CGI reads the CONTENT_LENGTHEPSS 0.3%CVE-2024-12345MEDIUMINW Krbyyyzo Daily Huddle Site gbo.aspx resource consumptionEPSS 0.3%CVE-2025-60638HIGHAn issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via crafted POST request to the NnssfEPSS 0.3%CVE-2026-77037HIGHmulter vulnerable to Denial of Service via file descriptor leak on aborted uploadsEPSS 0.3%CVE-2025-7579MEDIUMchinese-poetry server.js redosEPSS 0.3%CVE-2025-65947HIGHthread-amount is Vulnerable to Resource Exhaustion (Memory and Handle Leaks) on Windows and macOSEPSS 0.3%CVE-2025-64388CRITICALDenial of service through specific packetsEPSS 0.3%CVE-2025-70047HIGHAn issue pertaining to CWE-400: Uncontrolled Resource Consumption was discovered in Nexusoft NexusInterface v3.2.0-beta.2.EPSS 0.3%CVE-2014-2343—Triangle MicroWorks SCADA Data Gateway Resource ExhaustionEPSS 0.3%CVE-2025-30188HIGHMalicious or unintentional API requests can be used to add significant amount of data to caches. Caches may evict information that is requirEPSS 0.3%CVE-2026-22228MEDIUMImproper Input Validation Leading to DoS on TP-Link Archer BE230EPSS 0.3%CVE-2024-8892MEDIUMUncontrolled Resource Consumption vulnerability on CIRCUTOR TCP2RS+EPSS 0.3%CVE-2026-17463MEDIUMIBM® Db2® could allow a remote authenticated attacker to cause a denial of service due to uncontrolled resource consumptionEPSS 0.3%CVE-2026-22740MEDIUMSpring Framework DoS with Multipart Temp Files in WebFluxEPSS 0.3%CVE-2020-18770—An issue was discovered in function zzip_disk_entry_to_file_header in mmapped.c in zziplib 0.13.69, which will lead to a denial-of-service.EPSS 0.3%CVE-2026-100661HIGHNetty HTTP/3 QPACK Prefixed Integer DoS via Unbounded AccumulationEPSS 0.3%CVE-2026-100662HIGHNetty HTTP/3 QPACK encoder-stream unbounded memory exhaustion DoSEPSS 0.3%CVE-2026-66071MEDIUMRabbitMQ: Atom exhaustion: OAuth2 JWT tag: scope valuesEPSS 0.3%CVE-2025-29490MEDIUMlibming v0.4.8 was discovered to contain a segmentation fault via the decompileCALLMETHOD function. This vulnerability allows attackers to cEPSS 0.3%CVE-2025-65781HIGHAn issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Attachment upload API treats the AEPSS 0.3%