Fallos del tipo CWE-400

3000 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2024-23443MEDIUMA high-privileged user, allowed to create custom osquery packs 17 could affect the availability of Kibana by uploading a maliciously craftedEPSS 1.8%CVE-2020-3533HIGHCisco Firepower Threat Defense Software SNMP Denial of Service VulnerabilityEPSS 1.8%CVE-2018-13296HIGHUncontrolled resource consumption vulnerability in TLS configuration in Synology MailPlus Server before 2.0.5-0606 allows remote attackers tEPSS 1.8%CVE-2016-10540—Minimatch is a minimal matching utility that works by converting glob expressions into JavaScript `RegExp` objects. The primary function, `mEPSS 1.8%CVE-2017-16114—The marked module is vulnerable to a regular expression denial of service. Based on the information published in the public issue, 1k characEPSS 1.8%CVE-2025-33068HIGHWindows Standards-Based Storage Management Service Denial of Service VulnerabilityEPSS 1.8%CVE-2024-33655HIGHThe DNS protocol in RFC 1035 and updates allows remote attackers to cause a denial of service (resource consumption) by arranging for DNS quEPSS 1.7%CVE-2022-40617HIGHstrongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and iEPSS 1.7%CVE-2021-21271MEDIUMDenial of service in TenderMint CoreEPSS 1.7%CVE-2021-41115MEDIUMRegular expression denial-of-service in ZulipEPSS 1.7%CVE-2023-21543HIGHWindows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution VulnerabilityEPSS 1.7%CVE-2023-42669MEDIUMSamba: "rpcecho" development server allows denial of service via sleep() call on ad dcEPSS 1.7%CVE-2019-19300HIGHA vulnerability has been identified in Development/Evaluation Kits for PROFINET IO: EK-ERTEC 200, Development/Evaluation Kits for PROFINET IEPSS 1.7%CVE-2018-16491—A prototype pollution vulnerability was found in node.extend <1.1.7, ~<2.0.1 that allows an attacker to inject arbitrary properties onto ObjEPSS 1.7%CVE-2019-18336HIGHA vulnerability has been identified in SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions < V3.X.17), SIEPSS 1.7%CVE-2023-22796—A regular expression based DoS vulnerability in Active Support <6.1.7.1 and <7.0.4.1. A specially crafted string passed to the underscore meEPSS 1.7%CVE-2020-8237—Prototype pollution in json-bigint npm package < 1.0.0 may lead to a denial-of-service (DoS) attack.EPSS 1.7%CVE-2019-0031HIGHJunos OS: jdhcpd daemon memory consumption Denial of Service when receiving specific IPv6 DHCP packets.EPSS 1.7%CVE-2019-13940MEDIUMA vulnerability has been identified in SIMATIC ET 200pro IM154-8 PN/DP CPU (All versions < V3.X.17), SIMATIC ET 200pro IM154-8F PN/DP CPU (AEPSS 1.7%CVE-2024-23952MEDIUMApache Superset: Allows for uncontrolled resource consumption via a ZIP bomb (version range fix for CVE-2023-46104)EPSS 1.7%