Fallos del tipo CWE-400

3026 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2021-29506MEDIUMNavigate endpoint is vulnerable to regex injection that may lead to Denial of Service.EPSS 1.4%CVE-2019-10923HIGHAn attacker with network access to an affected product may cause a denial of service condition by breaking the real-time synchronization (IREPSS 1.4%CVE-2025-49716HIGHWindows Netlogon Denial of Service VulnerabilityEPSS 1.4%CVE-2016-10539—negotiator is an HTTP content negotiator for Node.js and is used by many modules and frameworks including Express and Koa. The header for "AEPSS 1.4%CVE-2024-40634HIGHArgo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook EndpointEPSS 1.4%CVE-2021-22116—RabbitMQ all versions prior to 3.8.16 are prone to a denial of service vulnerability due to improper input validation in AMQP 1.0 client conEPSS 1.4%CVE-2022-38150MEDIUMIn Varnish Cache 7.0.0, 7.0.1, 7.0.2, and 7.1.0, it is possible to cause the Varnish Server to assert and automatically restart through forgEPSS 1.4%CVE-2023-50967HIGHlatchset jose through version 11 allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.EPSS 1.4%CVE-2021-43838MEDIUMRegular Expression Denial of Service (ReDoS) in jsx-slackEPSS 1.4%CVE-2021-20185—It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that messaging did not impose a character limit when sending messages,EPSS 1.4%CVE-2020-27782—A flaw was found in the Undertow AJP connector. Malicious requests and abrupt connection closes could be triggered by an attacker using querEPSS 1.4%CVE-2020-3571HIGHCisco Firepower 4110 ICMP Flood Denial of Service VulnerabilityEPSS 1.4%CVE-2023-25816MEDIUMnextcloud vulnerable to Uncontrolled Resource ConsumptionEPSS 1.4%CVE-2022-38371HIGHA vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (EPSS 1.4%CVE-2018-6346HIGHA potential denial-of-service issue in the Proxygen handling of invalid HTTP2 priority settings (specifically a circular dependency). This aEPSS 1.4%CVE-2018-6347HIGHAn issue in the Proxygen handling of HTTP2 parsing of headers/trailers can lead to a denial-of-service attack. This affects Proxygen prior tEPSS 1.4%CVE-2025-24126CRITICALAn input validation issue was addressed. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS VenEPSS 1.4%CVE-2023-3163LOWy_project RuoYi filterKeyword resource consumptionEPSS 1.4%CVE-2020-25630—A vulnerability was found in Moodle where the decompressed size of zip files was not checked against available user quota before unzipping tEPSS 1.4%CVE-2019-19301HIGHA vulnerability has been identified in SCALANCE X200-4P IRT, SCALANCE X201-3P IRT, SCALANCE X201-3P IRT PRO, SCALANCE X202-2IRT, SCALANCE X2EPSS 1.4%