Fallos del tipo CWE-400

3051 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2026-39396LOWOpenBao has Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)EPSS 0.3%CVE-2026-23824HIGHUnauthenticated Denial-of-Service via Crafted Messages in a Network Protocol Handling ComponentEPSS 0.3%CVE-2026-47734MEDIUMDulwich has unbounded memory allocation in receive-pack from crafted thin packsEPSS 0.3%CVE-2023-38210MEDIUMOther | Uncontrolled Resource Consumption (CWE-400)EPSS 0.3%CVE-2025-50861MEDIUMThe Lotus Cars Android app (com.lotus.carsdomestic.intl) 1.2.8 contains an exported component, PushDeepLinkActivity, which is accessible witEPSS 0.3%CVE-2026-21723MEDIUMCVE-2026-21723 RecordEPSS 0.3%CVE-2026-60213MEDIUMVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.EPSS 0.3%CVE-2024-50354MEDIUMOut-of-memory during deserialization with crafted inputsEPSS 0.3%CVE-2025-57751HIGHDenial-of-Service attack in pyLoad CNL Blueprint using dukpy.evaljsEPSS 0.3%CVE-2025-25208MEDIUMRhcl: authorino denial of service through authpolicy with sharedsecretref severityEPSS 0.3%CVE-2024-22588MEDIUMKwik commit 745fd4e2 does not discard unused encryption keys.EPSS 0.3%CVE-2026-21998MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.EPSS 0.3%CVE-2026-22005MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.EPSS 0.3%CVE-2025-43706HIGHAn issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2400, 1580, 9110, W920,EPSS 0.3%CVE-2026-22004MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0EPSS 0.3%CVE-2026-22002MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.EPSS 0.3%CVE-2026-87722HIGHRegular Expression Denial of Service (ReDoS) in Search Query Predicates and REST Filter Endpoints in Gerrit Code ReviewEPSS 0.3%CVE-2026-87721HIGHDenial of Service via Exponential Backtracking in ANTLR Search Query Parser in Gerrit Code ReviewEPSS 0.3%CVE-2026-86420MEDIUMImageMagick before 7.1.2-30 Denial of Service Memory BudgetEPSS 0.3%CVE-2025-8849MEDIUMDenial of Service in danny-avila/librechatEPSS 0.3%