Fallos del tipo CWE-400

3053 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2026-46914HIGHVulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is affected is 11.4. EasEPSS 0.2%CVE-2025-69646MEDIUMBinutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logEPSS 0.2%CVE-2026-100242—DataTransfer depends on phpspreadsheet version vulnerable to CVE-2026-59933 (XLS/OLE memory exhaustion)EPSS 0.2%CVE-2023-31889MEDIUMAn issue discovered in httpd in ASUS RT-AC51U with firmware version up to and including 3.0.0.4.380.8591 allows local attackers to cause a dEPSS 0.2%CVE-2026-34281MEDIUMVulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11.4. Easily EPSS 0.2%CVE-2026-61052MEDIUMVulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems). The supported version that is affected is 11.4. EaEPSS 0.2%CVE-2026-87279MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.2%CVE-2024-3297MEDIUMSession establishment lock-up during replay of CASE Sigma1 messagesEPSS 0.2%CVE-2026-47044MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.2%CVE-2025-70347MEDIUMAn issue in mquickjs before commit 74b7e (2026-01-15) allows a local attacker to cause a denial of service via a crafted file to the get_mblEPSS 0.2%CVE-2026-47022LOWVulnerability in the GoldenGate Stream Analytics product of Oracle GoldenGate (component: Security). The supported version that is affecteEPSS 0.1%CVE-2024-54192MEDIUMAn issue inTcpreplay v4.5.1 allows a local attacker to cause a denial of service via a crafted file to the tcpedit_dlt_getplugin function atEPSS 0.1%CVE-2026-20602MEDIUMThe issue was addressed with improved handling of caches. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3EPSS 0.1%CVE-2026-6844MEDIUMBinutils: binutils: denial of service vulnerabilities in readelf via crafted elf filesEPSS 0.1%CVE-2025-9092LOWHybrid Module Deployment in Multi-JVM Environments Leading to Resource ExhaustionEPSS 0.1%CVE-2025-53068MEDIUMVulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exEPSS 0.1%CVE-2026-93587MEDIUMImageMagick before 7.1.2-31 Policy Bypass via PCD decoderEPSS 0.1%CVE-2025-66861LOWAn issue was discovered in function d_unqualified_name in file cp-demangle.c in BinUtils 2.26 allowing attackers to cause a denial of servicEPSS 0.1%CVE-2025-52636LOWHCL AION is affected by a improper handling of uploads files SizeEPSS 0.1%CVE-2022-38687MEDIUMIn messaging service, there is a missing permission check. This could lead to local denial of service in messaging service with no additionaEPSS 0.1%