Fallos del tipo CWE-400

2985 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2024-43515HIGHInternet Small Computer Systems Interface (iSCSI) Denial of Service VulnerabilityEPSS 2.3%CVE-2021-20216—A flaw was found in Privoxy in versions before 3.0.31. A memory leak that occurs when decompression fails unexpectedly may lead to a denial EPSS 2.3%CVE-2025-27470HIGHWindows Standards-Based Storage Management Service Denial of Service VulnerabilityEPSS 2.3%CVE-2025-26652HIGHWindows Standards-Based Storage Management Service Denial of Service VulnerabilityEPSS 2.3%CVE-2018-15464MEDIUMCisco ASR 900 Series Aggregation Services Router Software Denial of Service VulnerabilityEPSS 2.3%CVE-2019-1704HIGHCisco Firepower Threat Defense Software SMB Protocol Preprocessor Detection Engine Denial of Service VulnerabilitiesEPSS 2.2%CVE-2024-38149HIGHBranchCache Denial of Service VulnerabilityEPSS 2.2%CVE-2020-14340—A vulnerability was discovered in XNIO where file descriptor leak caused by growing amounts of NIO Selector file handles between garbage colEPSS 2.2%CVE-2023-33141HIGHYet Another Reverse Proxy (YARP) Denial of Service VulnerabilityEPSS 2.2%CVE-2024-43545HIGHWindows Online Certificate Status Protocol (OCSP) Server Denial of Service VulnerabilityEPSS 2.2%CVE-2024-43544HIGHMicrosoft Simple Certificate Enrollment Protocol Denial of Service VulnerabilityEPSS 2.2%CVE-2021-41186MEDIUMReDoS vulnerability in parser_apache2EPSS 2.2%CVE-2022-26477—Denial of service in readExternal methodEPSS 2.2%CVE-2021-32740HIGHRegular Expression Denial of Service in Addressable templatesEPSS 2.2%CVE-2021-22965—A vulnerability in Pulse Connect Secure before 9.1R12.1 could allow an unauthenticated administrator to causes a denial of service when a maEPSS 2.2%CVE-2022-21670MEDIUMUncontrolled Resource Consumption in markdown-itEPSS 2.2%CVE-2025-26641HIGHMicrosoft Message Queuing (MSMQ) Denial of Service VulnerabilityEPSS 2.2%CVE-2025-27473HIGHHTTP.sys Denial of Service VulnerabilityEPSS 2.2%CVE-2020-8185—A denial of service vulnerability exists in Rails <6.0.3.2 that allowed an untrusted user to run any pending migrations on a Rails app runniEPSS 2.2%CVE-2020-3131MEDIUMCisco Webex Teams Adaptive Cards Denial of Service VulnerabilityEPSS 2.2%