Fallos del tipo CWE-400

3051 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2026-90554MEDIUMvLLM before 0.28.0 Denial of Service via audio extractionEPSS 0.2%CVE-2024-22102MEDIUMDenial of Service (DoS) vulnerability in Jungo WinDriver before 12.6.0 allows local attackers to cause a Windows blue screen error.EPSS 0.2%CVE-2024-13065MEDIUMBusiness Logic Error in Akinsoft's MyRezztaEPSS 0.2%CVE-2024-21823HIGHHardware logic with insecure de-synchronization in Intel(R) DSA and Intel(R) IAA for some Intel(R) 4th or 5th generation Xeon(R) processors EPSS 0.2%CVE-2026-3293MEDIUMsnowflakedb snowflake-jdbc JDBC URL SdkProxyRoutePlanner.java SdkProxyRoutePlanner redosEPSS 0.2%CVE-2023-27734MEDIUMAn issue found in Eteran edb-debugger v.1.3.0 allows a local attacker to causea denial of service via the collect_symbols function in pluginEPSS 0.2%CVE-2025-43235MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6. An app may be able to cause a denial-of-seEPSS 0.2%CVE-2023-3108MEDIUMKernel: a race condition in crypto module in the function skcipher_recvmsgEPSS 0.2%CVE-2026-8124MEDIUMGPAC box_code_base.c sidx_box_read allocation of resourcesEPSS 0.2%CVE-2025-4001MEDIUMscipopt scip File Descriptor genRandomLOPInstance.c main file descriptor consumptionEPSS 0.2%CVE-2025-27087MEDIUMA vulnerability in the kernel of the Cray Operating System (COS) could allow an attacker to perform a local Denial of Service (DoS) attack.EPSS 0.2%CVE-2019-25721HIGHDräger Infinity M300 VG2.3.1 Network-Based Denial of ServiceEPSS 0.2%CVE-2025-50096MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.42, 8.4.0EPSS 0.2%CVE-2026-53937MEDIUMMCP Kotlin SDK's unbounded line buffer in StdioServerTransport/StdioClientTransport leads to memory exhaustion (DoS)EPSS 0.2%CVE-2026-81720MEDIUMopenssl_encrypt before 1.4.9 Denial of Service via Unbounded Argon2EPSS 0.2%CVE-2022-39165MEDIUMIBM AIX denial of serviceEPSS 0.2%CVE-2022-39164MEDIUMIBM AIX denial of serviceEPSS 0.2%CVE-2026-58203MEDIUMNestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_sizeEPSS 0.2%CVE-2026-28575CRITICALIn PackageInstaller.Session#transfer of frameworks/base/services/core/java/com/android/server/pm/PackageInstallerSession.java, there is a poEPSS 0.2%CVE-2026-63119MEDIUMMCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)EPSS 0.2%