Fallos del tipo CWE-400

3051 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2026-100558HIGHOpenClaw before 2026.8.1 Resource Exhaustion via WebSocket UpgradeEPSS 0.3%CVE-2026-67228MEDIUMRabbitMQ: Atom exhaustion: to_atom on runtime-parameter componentEPSS 0.3%CVE-2024-31994MEDIUMMealie vulnerable to a DoS in recipe image importer (GHSL-2023-228)EPSS 0.3%CVE-2025-57440HIGHThe Blackmagic ATEM Mini Pro 2.7 exposes an undocumented Telnet service on TCP port 9993, which accepts unauthenticated plaintext commands fEPSS 0.3%CVE-2026-10156MEDIUMOpen5GS nf-instances Endpoint nnrf-handler.c handle_amf_info resource consumptionEPSS 0.3%CVE-2024-33259MEDIUMJerryscript commit cefd391 was discovered to contain a segmentation violation via the component scanner_seek at jerry-core/parser/js/js-scanEPSS 0.3%CVE-2024-53423MEDIUMAn issue in Open Network Foundation ONOS v2.7.0 allows attackers to cause a Denial of Service (DoS) via supplying crafted packets.EPSS 0.3%CVE-2024-42397MEDIUMUnauthenticated Denial-of-Service (DoS) Vulnerabilities in the AP Certificate Management Service Accessed by the PAPI ProtocolEPSS 0.3%CVE-2026-34673MEDIUMCAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)EPSS 0.3%CVE-2025-49460MEDIUMZoom Workplace Clients - Argument InjectionEPSS 0.3%CVE-2021-33135MEDIUMUncontrolled resource consumption in the Linux kernel drivers for Intel(R) SGX may allow an authenticated user to potentially enable denial EPSS 0.3%CVE-2021-3764—A memory leak flaw was found in the Linux kernel's ccp_run_aes_gcm_cmd() function that allows an attacker to cause a denial of service. The EPSS 0.3%CVE-2026-61247MEDIUMVulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that EPSS 0.3%CVE-2026-96764MEDIUMkvcache-ai mooncake Regular Expression GetReplicaListByRegex allocation of resourcesEPSS 0.3%CVE-2025-66453MEDIUMRhino vulnerable high CPU usage and potential DoS when passing specific numbers to toFixed() functionEPSS 0.3%CVE-2026-60669MEDIUMVulnerability in the PeopleSoft Enterprise HCM Global Payroll Mexico product of Oracle PeopleSoft (component: Global Payroll for Mexico). EPSS 0.3%CVE-2026-61123MEDIUMVulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affeEPSS 0.3%CVE-2025-24199MEDIUMAn uncontrolled format string issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14EPSS 0.3%CVE-2026-36605MEDIUMMercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 is vulnerable to a HTTP denial of service via a low number of crafted incompEPSS 0.3%CVE-2026-9002MEDIUMIBM WebSphere eXtremes Scale is affected by uncontrolled resource consumption when XDF is enabledEPSS 0.3%