Fallos del tipo CWE-400

3054 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2026-103000HIGHpypdf: Possible large memory usage when retrieving alphabetical page labelsEPSS —CVE-2026-47568MEDIUMNVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where a user could cause uncontrolled kernel log generEPSS —CVE-2026-86344HIGH389-ds-base: 389-ds-base: unauthenticated worker-thread-pool exhaustion via completed-operation-then-incomplete-pdu connection requeueEPSS —CVE-2026-102995HIGHpypdf: Possible large memory usage for large /ToUnicode streams (Follow-up 2)EPSS —CVE-2026-102999HIGHpypdf: Possible long runtimes with large amount of embedded filesEPSS —CVE-2026-102997HIGHpypdf: Possible long runtimes for partially malformed FlateDecode streams (Follow-up)EPSS —CVE-2026-102993HIGHpypdf: Possible large memory usage when retrieving Roman page labelsEPSS —CVE-2026-102994HIGHpypdf: Possible long runtimes/large memory usage when parsing indirect objectsEPSS —CVE-2026-102998HIGHpypdf: Possible long runtimes when generating appearance streamsEPSS —CVE-2026-102144MEDIUMKiteworks Email Protection Gateway Uncontrolled Resource ConsumptionEPSS —CVE-2026-68496HIGHjackson-dataformats-binary: Smile parser does not enforce StreamReadConstraints.maxNameLength, enabling memory-exhaustion denial of serviceEPSS —CVE-2026-102996HIGHpypdf: Possible large memory usage when parsing font dataEPSS —CVE-2026-47567MEDIUMNVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where a user could cause uncontrolled resource consumEPSS —CVE-2026-68495HIGHjackson-dataformats-binary: CBOR parser does not enforce StreamReadConstraints.maxNameLength, enabling memory-exhaustion denial of serviceEPSS —