Fallos del tipo CWE-400

3051 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2026-24738MEDIUMgmrtd ReadFile Vulnerable to Denial of Service via Excessive TLV Length ValuesEPSS 0.3%CVE-2026-30955MEDIUMGokapi vulnerable to DoS in E2E Metadata ParserEPSS 0.3%CVE-2026-102414MEDIUMpbkdf2 rehashes long passwords on every iteration, enabling denial of serviceEPSS 0.3%CVE-2024-14036HIGHDräger Core 1.0.5 Denial of Service via Malformed SDC MessageEPSS 0.3%CVE-2025-69654HIGHA crafted JavaScript input executed with the QuickJS release 2025-09-13, fixed in commit fcd33c1afa7b3028531f53cd1190a3877454f6b3 (2025-12-1EPSS 0.3%CVE-2026-74797LOWOpenTofu before 1.11.4 Denial of Service via malicious zipEPSS 0.3%CVE-2026-29776LOWFreeRDP has an Integer Underflow in update_read_cache_bitmap_order Function of FreeRDP's Core LibraryEPSS 0.3%CVE-2026-19401HIGHRemote UDP DoS by sending multiple DNS Cookie optionsEPSS 0.3%CVE-2026-81723MEDIUMNLTK before 3.10.3 Quadratic CPU Exhaustion via XMLCorpusViewEPSS 0.3%CVE-2026-44456MEDIUMHono: bodyLimit() can be bypassed for chunked / unknown-length requestsEPSS 0.3%CVE-2026-17465MEDIUMMultiple Vulnerabilities in IBM Concert SoftwareEPSS 0.3%CVE-2025-61155MEDIUMThe GameDriverX64.sys kernel-mode anti-cheat driver (v7.23.4.7 and earlier) contains an access control vulnerability in one of its IOCTL hanEPSS 0.3%CVE-2024-54113MEDIUMProcess residence vulnerability in abnormal scenarios in the print module Impact: Successful exploitation of this vulnerability may affect pEPSS 0.3%CVE-2026-100558HIGHOpenClaw before 2026.8.1 Resource Exhaustion via WebSocket UpgradeEPSS 0.3%CVE-2026-67229MEDIUMRabbitMQ: Admin-only atom exhaustion: atomize_keys on vhost metadataEPSS 0.3%CVE-2025-65122HIGHRegex Denial of Service in youtube-regex npm package through version 1.0.5.EPSS 0.3%CVE-2024-44154MEDIUMA memory initialization issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7. ProceEPSS 0.3%CVE-2025-54324HIGHAn issue was discovered in NAS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330EPSS 0.3%CVE-2025-56352HIGHIn tinyMQTT commit 6226ade15bd4f97be2d196352e64dd10937c1962 (2024-02-18), the broker mishandles protocol violations during CONNECT packet paEPSS 0.3%CVE-2024-31994MEDIUMMealie vulnerable to a DoS in recipe image importer (GHSL-2023-228)EPSS 0.3%