Fallos del tipo CWE-400

3051 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2021-3669—A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segment counts which coulEPSS 0.3%CVE-2026-73746LOWAuthenticated Denial of Service Vulnerability in HPE Networking Fabric Composer APIEPSS 0.3%CVE-2026-22541HIGHDENIAL OF SERVICE VIA ICMP PACKETSEPSS 0.3%CVE-2023-5595MEDIUMDenial of Service in gpac/gpacEPSS 0.3%CVE-2025-27829HIGHAn issue was discovered in Stormshield Network Security (SNS) 4.3.x before 4.3.35. If multicast streams are enabled on different interfaces,EPSS 0.3%CVE-2020-24089—An issue was discovered in ImfHpRegFilter.sys in IOBit Malware Fighter version 8.0.2, allows local attackers to cause a denial of service (DEPSS 0.3%CVE-2025-69199HIGHPterodactyl Wings's websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks under certain circumstancesEPSS 0.3%CVE-2026-81687HIGHopenssl_encrypt before 1.4.9 Denial of Service via KDFEPSS 0.3%CVE-2026-11790MEDIUM389-ds-base: 389-ds-base: pbkdf2 password storage plugin unbounded iteration count denial of serviceEPSS 0.3%CVE-2026-73759MEDIUMUnauthenticated Denial-of-Service Vulnerabilities in AOS-CXEPSS 0.3%CVE-2026-19645MEDIUMMultiple vulnerabilities in IBM MQ Agent imagesEPSS 0.3%CVE-2026-21588HIGHThis High severity DoS (Denial of Service) vulnerability was introduced in versions 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2,EPSS 0.3%CVE-2026-67220MEDIUMRabbitMQ: JMS topic exchange erl_scan atom exhaustionEPSS 0.3%CVE-2023-21061—Product: AndroidVersions: Android kernelAndroid ID: A-229255400References: N/AEPSS 0.3%CVE-2026-42073MEDIUMOpenClaude's MCP OAuth Callback: State Check Bypass via error Param Leads to DoSEPSS 0.3%CVE-2026-73744LOWAuthenticated Denial of Service Vulnerability in HPE Networking Fabric Composer Web-Based Management InterfaceEPSS 0.3%CVE-2026-67227MEDIUMRabbitMQ: Atom exhaustion: to_atom on global-parameter :nameEPSS 0.3%CVE-2026-74903MEDIUMSiYuan before v3.7.4 Insufficient Access Control via spinBlockDOMEPSS 0.3%CVE-2026-10705LOWdask HLL hyperloglog.py nunique_approx resource consumptionEPSS 0.3%CVE-2024-1816MEDIUMUncontrolled Resource Consumption in GitLabEPSS 0.3%