Fallos del tipo CWE-400

3051 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2025-8872HIGHA specially crafted packet can cause the OSFPv3 process to have high CPU utilization which may result in the OSFPv3 process being restartedEPSS 0.3%CVE-2026-59980MEDIUMhpack: Unbounded variable integer decoding can cause run-away computation on malformed inputEPSS 0.3%CVE-2026-21956HIGHVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.EPSS 0.3%CVE-2026-21955HIGHVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.EPSS 0.3%CVE-2026-6051MEDIUMIBM® Db2® is vulnerable to a denial of service when executing a specially crafted query with a small statement heapEPSS 0.3%CVE-2024-57082MEDIUMA prototype pollution in the lib.createUploader function of @rpldy/uploader v1.8.1 allows attackers to cause a Denial of Service (DoS) via sEPSS 0.3%CVE-2022-0669—A flaw was found in dpdk. This flaw allows a malicious vhost-user master to attach an unexpected number of fds as ancillary data to VHOST_USEPSS 0.3%CVE-2024-53647MEDIUMTrend Micro ID Security, version 3.0 and below contains a vulnerability that could allow an attacker to send an unlimited number of email veEPSS 0.3%CVE-2024-1930MEDIUMNo Limit on Number of Open Sessions / Bad Session Close BehaviourEPSS 0.3%CVE-2022-36329MEDIUMDenial of Service over OTA mechanism in Western Digital My Cloud Home and ibi devicesEPSS 0.3%CVE-2023-20047MEDIUMA vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco Webex Room Phone and Cisco Webex Share devices could allow an uEPSS 0.3%CVE-2026-65827MEDIUMDocmost: Unbounded ZIP decompression (zip-bomb) in page import allows denial of serviceEPSS 0.3%CVE-2020-37277HIGHPocketMine-MP before 3.15.4 Denial of Service via InventoryTransactionEPSS 0.3%CVE-2025-53636MEDIUMOpen OnDemand Shell App closed websocket DoSEPSS 0.3%CVE-2026-102821MEDIUMRussh: Unbounded memory exhaustion via CHANNEL_OPEN flood during a client-stalled rekeyEPSS 0.3%CVE-2026-62508LOWVulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that areEPSS 0.3%CVE-2026-60936LOWVulnerability in the Oracle Labor Distribution product of Oracle E-Business Suite (component: Internal Operations). Supported versions thatEPSS 0.3%CVE-2026-34277MEDIUMVulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Fluid Core). Supported versions that are afEPSS 0.3%CVE-2026-83369LOWVulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Access SDK). Supported versions that are affecteEPSS 0.3%CVE-2026-61048LOWVulnerability in the Oracle Inventory Optimization product of Oracle E-Business Suite (component: User Interface). Supported versions that EPSS 0.3%