Fallos del tipo CWE-400

3026 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2026-55440MEDIUMMicrosoft UFO: COMMAND_RESULTS handler creates unowned sessions, allowing authenticated session-squatting denial of serviceEPSS 1.3%CVE-2022-3257LOWServer-side Denial of Service while processing a specifically crafted GIF fileEPSS 1.3%CVE-2022-4896HIGHCyber Control, in its 1.650 version, is affected by a vulnerability in the generation on the server of pop-up windows with the messages "PNTEPSS 1.3%CVE-2024-23450MEDIUMElasticsearch Uncontrolled Resource Consumption vulnerabilityEPSS 1.3%CVE-2024-24814HIGHDenial of service when manipulating mod_auth_openidc_session_chunks cookie in mod_auth_openidcEPSS 1.3%CVE-2018-17898—Yokogawa STARDOM Controllers FCJ,FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The controller application fails to prevent memoryEPSS 1.3%CVE-2022-3411MEDIUMA lack of length validation in GitLab CE/EE affecting all versions from 12.4 before 15.6.7, 15.7 before 15.7.6, and 15.8 before 15.8.1 allowEPSS 1.2%CVE-2020-1722MEDIUMA flaw was found in all ipa versions 4.x.x through 4.8.0. When sending a very long password (>= 1,000,000 characters) to the server, the pasEPSS 1.2%CVE-2022-21708MEDIUMDenial of Service in graphql-goEPSS 1.2%CVE-2023-1733MEDIUMA denial of service condition exists in the Prometheus server bundled with GitLab affecting all versions from 11.10 to 15.8.5, 15.9 to 15.9.EPSS 1.2%CVE-2020-3305MEDIUMCisco Adaptive Security Appliance Software and Firepower Threat Defense Software BGP Denial of Service VulnerabilityEPSS 1.2%CVE-2020-3306MEDIUMCisco Adaptive Security Appliance Software and Firepower Threat Defense Software DHCP Denial of Service VulnerabilityEPSS 1.2%CVE-2018-10864MEDIUMAn uncontrolled resource consumption flaw has been discovered in redhat-certification in the way documents are loaded. A remote attacker mayEPSS 1.2%CVE-2023-2263HIGHRockwell Automation Kinetix 5700 DC Bus Power Supply Series A – CIP Message Attack Could Cause Denial-Of-ServiceEPSS 1.2%CVE-2020-14326—A vulnerability was found in RESTEasy, where RootNode incorrectly caches routes. This issue results in hash flooding, leading to slower requEPSS 1.2%CVE-2023-2778HIGHRockwell Automation FactoryTalk Transaction Manager Vulnerable to Denial-Of-ServiceEPSS 1.2%CVE-2024-42849MEDIUMAn issue in Silverpeas v.6.4.2 and lower allows a remote attacker to cause a denial of service via the password change function.EPSS 1.2%CVE-2023-50685HIGHAn issue in Hipcam Cameras RealServer v.1.0 allows a remote attacker to cause a denial of service via a crafted script to the client_port paEPSS 1.2%CVE-2022-3759MEDIUMAn issue has been discovered in GitLab CE/EE affecting all versions starting from 14.3 before 15.6.7, all versions starting from 15.7 beforeEPSS 1.2%CVE-2023-0518MEDIUMAn issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0 before 15.6.7, all versions starting from 15.7 beforeEPSS 1.2%