Fallos del tipo CWE-400

3051 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2025-29490MEDIUMlibming v0.4.8 was discovered to contain a segmentation fault via the decompileCALLMETHOD function. This vulnerability allows attackers to cEPSS 0.3%CVE-2026-67408HIGHRabbitMQ: Stream Management Super-Stream Binding Keys Allocation Allows Low-Privilege Node Denial of ServiceEPSS 0.3%CVE-2024-7294HIGHUncontrolled resource consumption of anonymous endpointsEPSS 0.3%CVE-2026-22745MEDIUMCVE-2026-22745 : Denial of service in static resource handling on Windows platformsEPSS 0.3%CVE-2026-57962MEDIUMDenial-of-service via malicious LDAP address-book serverEPSS 0.3%CVE-2025-70059HIGHAn issue pertaining to CWE-400: Uncontrolled Resource Consumption was discovered in YMFE yapi v1.12.0 and allows attackers to cause a denialEPSS 0.3%CVE-2026-6060MEDIUMPossible DoS via SQL BoxEPSS 0.3%CVE-2021-20265—A flaw was found in the way memory resources were freed in the unix_stream_recvmsg function in the Linux kernel when a signal was pending. TEPSS 0.3%CVE-2026-44167HIGHphpseclib: CVE-2024-27355 mitigation bypass — OID amplification DoS in ASN1::decodeOID()EPSS 0.3%CVE-2026-73057HIGHstoatchat before 0.15.0 Uncapped SVG Rendering Denial of ServiceEPSS 0.3%CVE-2026-61192MEDIUMVulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version tEPSS 0.3%CVE-2020-15100LOWUncontrolled Resource Consumption in freewvsEPSS 0.3%CVE-2026-87267MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.3%CVE-2026-83251MEDIUMVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). TheEPSS 0.3%CVE-2025-55029HIGHMalicious scripts could spam popups for denial of service attacksEPSS 0.3%CVE-2024-25132MEDIUMOpenshift-dedicated: hive: hibernation controller denial of serviceEPSS 0.3%CVE-2025-6714HIGHIncorrect Handling of incomplete data may prevent mongoS from Accepting New ConnectionsEPSS 0.3%CVE-2026-73754MEDIUMAuthenticated Denial-of-Service Vulnerabilities in the Command Line Interface of AOS-CXEPSS 0.3%CVE-2025-56234HIGHAT_NA2000 from Nanda Automation Technology vendor has a denial-of-service vulnerability. For the processing of TCP RST packets, PLC AT_NA200EPSS 0.3%CVE-2025-53371CRITICALDiscordNotifications allows DOS, SSRF, and possible RCE through requests to user-controlled URLsEPSS 0.3%