Fallos del tipo CWE-400

3051 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2026-6777MEDIUMOther issue in the Networking: DNS componentEPSS 0.2%CVE-2026-12325MEDIUMDenial-of-service in the Graphics: ImageLib componentEPSS 0.2%CVE-2026-18105HIGHFireware OS Uncontrolled Resource Consumption in Diagnostic Tasks Allows Denial of ServiceEPSS 0.2%CVE-2021-47284MEDIUMisdn: mISDN: netjet: Fix crash in nj_probe:EPSS 0.2%CVE-2025-26472MEDIUMUncontrolled resource consumption for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platform may allow EPSS 0.2%CVE-2024-35948HIGHbcachefs: Check for journal entries overruning end of sb clean sectionEPSS 0.2%CVE-2021-4440HIGHx86/xen: Drop USERGS_SYSRET64 paravirt callEPSS 0.2%CVE-2025-13837LOWOut-of-memory when loading PlistEPSS 0.2%CVE-2024-34036MEDIUMAn issue was discovered in O-RAN Near Realtime RIC I-Release. To exploit this vulnerability, an attacker can disrupt the initial connection EPSS 0.2%CVE-2025-55028MEDIUMJavaScript alerts could impede UI interaction or allow denial of service attacksEPSS 0.2%CVE-2024-39479HIGHdrm/i915/hwmon: Get rid of devmEPSS 0.2%CVE-2021-25701—The fUSBHub driver in the PCoIP Software Client prior to version 21.07.0 had an error in object management during the handling of a variety EPSS 0.2%CVE-2025-20616LOWUncontrolled resource consumption for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated user to pEPSS 0.2%CVE-2024-25112MEDIUMDenial of service due to unbounded recursion in QuickTimeVideo::multipleEntriesDecoder in Exiv2EPSS 0.2%CVE-2026-49762MEDIUMUnbounded integer parsing in the Version module enables CPU and memory exhaustion denial of serviceEPSS 0.2%CVE-2023-4394MEDIUMMemory leak in btrfs_get_dev_args_from_path()EPSS 0.2%CVE-2026-12759MEDIUMMultiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation iFixes for August 2026.EPSS 0.2%CVE-2025-20084MEDIUMUncontrolled resource consumption for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated user to pEPSS 0.2%CVE-2025-20057MEDIUMUncontrolled resource consumption for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated user to pEPSS 0.2%CVE-2026-21500MEDIUMStack Overflow in iccDEV XML Calculator Macro ExpansionEPSS 0.2%