Fallos del tipo CWE-400

3051 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2025-56233HIGHOpenindiana, kernel SunOS 5.11 has a denial of service vulnerability. For the processing of TCP packets with RST or SYN flag set, OpenindianEPSS 0.3%CVE-2026-32686MEDIUMUnbounded exponent in decimal enables unauthenticated DoSEPSS 0.3%CVE-2026-40014MEDIUMAn attacker that can send mail to a user can craft a message header that makes the IMAP THREAD command consume CPU disproportionate to the sEPSS 0.3%CVE-2026-40017MEDIUMAn attacker that can send mail to a user can craft a message header whose values are chosen to collide in an internal hash table, which makeEPSS 0.3%CVE-2006-5649MEDIUMUnspecified vulnerability in the "alignment check exception handling" in Ubuntu 5.10, 6.06 LTS, and 6.10 for the PowerPC (PPC) allows local EPSS 0.3%CVE-2025-58451HIGHCattown Vulnerable to Inefficient Regular Expression Complexity and Uncontrolled Resource ConsumptionEPSS 0.3%CVE-2025-61595HIGHMANTRA tx gas limit is not enforced in send hooksEPSS 0.3%CVE-2025-49000LOWInvenTree has uncontrolled memory allocation via built-in label-sheet pluginEPSS 0.3%CVE-2025-62478MEDIUMVulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Object Store). The supported version that is aEPSS 0.3%CVE-2025-62477MEDIUMVulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Remote Replication). The supported version thaEPSS 0.3%CVE-2026-83968HIGHWindows Biometric Service Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2025-62475MEDIUMVulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Core). The supported version that is affected EPSS 0.3%CVE-2026-44242LOWMicronaut Framework: Unbounded bundleCache in ResourceBundleMessageSource Allows Memory Exhaustion via Accept-Language HeaderEPSS 0.3%CVE-2025-62476MEDIUMVulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Remote Replication). The supported version thaEPSS 0.3%CVE-2026-100648MEDIUMvllm before 0.29.0 Uncontrolled Resource Consumption via Audio DecodingEPSS 0.3%CVE-2026-66073MEDIUMRabbitMQ: Atom table exhaustion via management API node fieldEPSS 0.3%CVE-2025-49494HIGHAn issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 2100, 1280, 2200, 1330, 1380, 1480, 9110, Modem 51EPSS 0.3%CVE-2026-66072MEDIUMRabbitMQ: Atom table exhaustion via stream `chunk_selector`EPSS 0.3%CVE-2006-5648MEDIUMUbuntu Linux 6.10 for the PowerPC (PPC) allows local users to cause a denial of service (resource consumption) by using the (1) sys_get_robuEPSS 0.3%CVE-2026-39396LOWOpenBao has Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)EPSS 0.3%