Fallos del tipo CWE-400

3051 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2026-36605MEDIUMMercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 is vulnerable to a HTTP denial of service via a low number of crafted incompEPSS 0.3%CVE-2026-9002MEDIUMIBM WebSphere eXtremes Scale is affected by uncontrolled resource consumption when XDF is enabledEPSS 0.3%CVE-2026-76696MEDIUMUnauthenticated Denial-of-Service (DoS) Vulnerability leads to Service Disruption in HPE Networking EdgeConnect SD-WAN GatewaysEPSS 0.3%CVE-2026-44247MEDIUMVolcano: Webhook server vulnerable to OOM due to unbounded HTTP request body sizeEPSS 0.3%CVE-2025-48609CRITICALIn multiple functions of MmsProvider.java, there is a possible way to arbitrarily delete files which affect telephony, SMS, and MMS functionEPSS 0.3%CVE-2024-6126LOWCockpit: authenticated user can kill any process when enabling pam_env's user_readenv optionEPSS 0.3%CVE-2021-32699MEDIUMAsymmetric Resource Consumption (Amplification) in Docker containers created by WingsEPSS 0.3%CVE-2024-21161MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are PrioEPSS 0.3%CVE-2022-45873MEDIUMsystemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long backtrace. This occurs iEPSS 0.3%CVE-2025-59464MEDIUMA memory leak in Node.js’s OpenSSL integration occurs when converting `X.509` certificate fields to UTF-8 without freeing the allocated buffEPSS 0.3%CVE-2026-47262MEDIUMcontainerd image-triggered runtime DoS via unbounded group parsingEPSS 0.3%CVE-2026-48990MEDIUMjoserfc: b64=false RFC7797 JWS payloads bypass JWSRegistry payload-size limits during deserializationEPSS 0.3%CVE-2024-26976HIGHKVM: Always flush async #PF workqueue when vCPU is being destroyedEPSS 0.3%CVE-2025-22892HIGHUncontrolled resource consumption for some OpenVINO™ model server software maintained by Intel(R) before version 2024.4 may allow an unautheEPSS 0.3%CVE-2023-20268MEDIUMCisco Access Point Software Uncontrolled Resource Consumption VulnerabilityEPSS 0.3%CVE-2025-61478HIGHAn issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial ofEPSS 0.3%CVE-2026-71491HIGHsqlparse: Quadratic O(n²) DoS in group_commentsEPSS 0.3%CVE-2026-14321HIGHDivi Dash < 1.0.7 - Unauthenticated Denial of Service via IP Address SpoofingEPSS 0.3%CVE-2026-73175HIGHNozomi Networks Labs identified a CWE-400: Uncontrolled Resource Consumption vulnerability in the OPC UA gateway component of Advantech EKI-EPSS 0.3%CVE-2025-46171MEDIUMvBulletin 3.8.7 is vulnerable to a denial-of-service condition via the misc.php?do=buddylist endpoint. If an authenticated user has a sufficEPSS 0.3%