Fallos del tipo CWE-400

3051 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2024-20959MEDIUMVulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Core). The supported version that is affected EPSS 0.2%CVE-2025-40766MEDIUMA vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V3.0). The affected application runs dockEPSS 0.2%CVE-2026-30980MEDIUMiccDEV has a stack overflow in CIccBasicStructFactory::CreateStruct()EPSS 0.2%CVE-2026-71870MEDIUMpypdf: Possible large memory usage for large /ToUnicode streamsEPSS 0.2%CVE-2023-31348HIGHA DLL hijacking vulnerability in AMD μProf could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code EPSS 0.2%CVE-2025-36892HIGHDenial of serviceEPSS 0.2%CVE-2025-29477MEDIUMAn issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the function consume_event.EPSS 0.2%CVE-2026-82743LOWAsh.Actions.Read.AsyncLimiter busy-spins a scheduler while awaiting slow async readsEPSS 0.2%CVE-2026-81869MEDIUMOpenTelemetry-Go: UTF-8 replacement rune bypasses attribute length truncationEPSS 0.2%CVE-2023-20911HIGHIn addPermission of PermissionManagerServiceImpl.java , there is a possible failure to persist permission settings due to resource exhaustioEPSS 0.2%CVE-2026-82742MEDIUMAsh.Filter.Runtime materializes a combinatorial cross-product over to-many relationships, exhausting memoryEPSS 0.2%CVE-2026-82735MEDIUMMatch regex runs on over-length input in Ash.Type.String, enabling regex denial of serviceEPSS 0.2%CVE-2026-48155MEDIUMpypdf: Possible large memory usage for large offsets for layout mode textEPSS 0.2%CVE-2025-59529MEDIUMsimple protocol server ignores accepts unlimited connections and logs failures without limitEPSS 0.2%CVE-2026-27576MEDIUMOpenClaw: ACP prompt-size checks missing in local stdio bridge could reduce responsiveness with very large inputsEPSS 0.2%CVE-2026-43653MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS EPSS 0.2%CVE-2025-40802LOWA vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions). The affected device may be susceptible to resourceEPSS 0.2%CVE-2019-25724HIGHDräger Infinity M300 VG2.x Network-Based Denial of ServiceEPSS 0.2%CVE-2026-71642MEDIUMAn issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denEPSS 0.2%CVE-2023-25179MEDIUMUncontrolled resource consumption in the Intel(R) Unite(R) android application before Release 17 may allow an authenticated user to potentiaEPSS 0.2%