Fallos del tipo CWE-400

3051 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2026-2405MEDIUMCWE-400 Uncontrolled Resource Consumption vulnerability exists that could cause excessive troubleshooting zip file creation and denial of seEPSS 0.2%CVE-2024-34035MEDIUMAn issue was discovered in O-RAN Near Realtime RIC H-Release. To trigger the crashing of the e2mgr, an adversary must flood the system with EPSS 0.2%CVE-2026-11611MEDIUM389-ds-base: 389-ds-base: content sync plugin unbounded queue growth and race conditionsEPSS 0.2%CVE-2025-63811HIGHAn issue was discovered in dvsekhvalnov jose2go 1.5.0 thru 1.7.0 allowing an attacker to cause a Denial-of-Service (DoS) via crafted JSON WeEPSS 0.2%CVE-2025-69198MEDIUMPterodactyl's improper resource locking allows raced queries to create more resources than allotedEPSS 0.2%CVE-2023-39328MEDIUMOpenjpeg: denail of service via crafted image fileEPSS 0.2%CVE-2025-41226MEDIUMGuest Operations Denial-of-Service VulnerabilityEPSS 0.2%CVE-2025-6140MEDIUMspdlog pattern_formatter-inl.h scoped_padder resource consumptionEPSS 0.2%CVE-2026-55594MEDIUMImageMagick: Stack Overflow in MVG decoder due to missing depth check.EPSS 0.2%CVE-2024-26723HIGHlan966x: Fix crash when adding interface under a lagEPSS 0.2%CVE-2024-32902HIGHRemote prevention of access to cellular service with no user interaction (for example, crashing the cellular radio service with a malformed EPSS 0.2%CVE-2025-31226MEDIUMA logic issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, tvOS 1EPSS 0.2%CVE-2026-86608HIGHWP Recipe Maker 9.8.0 - 10.8.1 - Unauthenticated DoS via Unbounded User Meta InsertionEPSS 0.2%CVE-2023-42941MEDIUMThe issue was addressed with improved checks. This issue is fixed in iOS 17.2 and iPadOS 17.2. An attacker in a privileged network position EPSS 0.2%CVE-2024-37535MEDIUMGNOME VTE before 0.76.3 allows an attacker to cause a denial of service (memory consumption) via a window resize escape sequence, a related EPSS 0.2%CVE-2025-44559MEDIUMAn issue in the Bluetooth Low Energy (BLE) stack of Realtek RTL8762E BLE SDK v1.4.0 allows attackers within Bluetooth range to cause a DeniaEPSS 0.2%CVE-2024-38384HIGHblk-cgroup: fix list corruption from reorder of WRITE ->lqueuedEPSS 0.2%CVE-2021-47238MEDIUMnet: ipv4: fix memory leak in ip_mc_add1_srcEPSS 0.2%CVE-2026-20676MEDIUMThis issue was addressed through improved state management. This issue is fixed in Safari 26.3, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, EPSS 0.2%CVE-2025-30725MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.2%