Fallos del tipo CWE-400

3051 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2026-53495MEDIUMcontainerd CRI ExecSync Goroutine Leak Leading to Node-Level Denial of ServiceEPSS 0.2%CVE-2022-4816MEDIUMA denial-of-service vulnerability has been identified in Lenovo Safecenter that could allow a local user to crash the application.EPSS 0.2%CVE-2022-20482MEDIUMIn createNotificationChannel of NotificationManager.java, there is a possible way to make the device unusable and require factory reset due EPSS 0.2%CVE-2026-43768MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. AEPSS 0.2%CVE-2026-28932MEDIUMA logic issue existed resulting in memory corruption. This was addressed with improved state management. This issue is fixed in macOS SequoiEPSS 0.2%CVE-2026-55782LOWNanaZip: Unbounded memory allocation (DoS) in NanaZip WebAssembly parser via attacker-controlled section/name length fieldsEPSS 0.2%CVE-2025-60753MEDIUMAn issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c when processing craftedEPSS 0.2%CVE-2023-6450MEDIUMAn incorrect permissions vulnerability was reported in the Lenovo App Store app that could allow an attacker to use system resources, resultEPSS 0.2%CVE-2026-35901MEDIUMA handling issue in the RTSP service of the Mercury MIPC252W 1.0.5 Build 230306 Rel.79931n allows an authenticated attacker to trigger sessiEPSS 0.2%CVE-2025-9341MEDIUMGarbage collection can delay for AES CBC Native support, resulting in heap exhaustionEPSS 0.2%CVE-2026-14684MEDIUMHdrHistogram AbstractHistogram.java memory allocationEPSS 0.2%CVE-2026-71616MEDIUMAn issue in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an attacker to cause a denial of service via the function gf_route_media_coEPSS 0.2%CVE-2026-14683MEDIUMHdrHistogram AbstractHistogram.java memory allocationEPSS 0.2%CVE-2026-64724MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOEPSS 0.2%CVE-2026-4174MEDIUMRadare2 Mach-O File mach0.c walk_exports_trie resource consumptionEPSS 0.2%CVE-2026-52857MEDIUMWings: Maliciously or erroneously created parsed config files can cause wings process to OOMEPSS 0.2%CVE-2026-55781LOWNanaZip: Unbounded memory allocation (DoS) in NanaZip UFS parser via unvalidated fs_bsize/fs_fsize superblock fieldsEPSS 0.2%CVE-2026-4539MEDIUMpygments archetype.py AdlLexer redosEPSS 0.2%CVE-2026-55373MEDIUMOpenEXR: OpenEXRUtil SampleCountChannel endEdit() can loop forever on UINT_MAX sample countsEPSS 0.2%CVE-2025-12194MEDIUMUncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java FIPS bc-fips on All (API modules)EPSS 0.2%