Fallos del tipo CWE-400

3026 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2021-1266MEDIUMCisco Managed Services Accelerator Denial of Service VulnerabilityEPSS 1.1%CVE-2026-49799MEDIUMWindows Local Security Authority Subsystem Service (LSASS) Denial of Service VulnerabilityEPSS 1.1%CVE-2022-29177MEDIUMDoS via malicious p2p message in Go-EthereumEPSS 1.1%CVE-2026-21637MEDIUMA flaw in Node.js TLS error handling allows remote attackers to crash or exhaust resources of a TLS server when `pskCallback` or `ALPNCallbaEPSS 1.1%CVE-2023-34104HIGHRegex Injection via Doctype EntitiesEPSS 1.1%CVE-2022-31803MEDIUMCODESYS Gateway Server V2 prone to Denial of Service AttackEPSS 1.1%CVE-2022-31006HIGHHyperledger Indy DOS vulnerabilityEPSS 1.1%CVE-2022-48748HIGHnet: bridge: vlan: fix memory leak in __allowed_ingressEPSS 1.1%CVE-2024-27812HIGHA logic issue was addressed with improved file handling. This issue is fixed in visionOS 1.2. Processing web content may lead to a denial-ofEPSS 1.1%CVE-2021-31405HIGHRegular expression denial of service (ReDoS) in EmailField component in Vaadin 14 and 15-17EPSS 1.1%CVE-2023-31409MEDIUMUncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 112252EPSS 1.1%CVE-2017-16111—The content module is a module to parse HTTP Content-* headers. It is used by the hapijs framework to provide this functionality. The moduleEPSS 1.1%CVE-2022-39271HIGHTraefik HTTP/2 connections management could cause a denial of serviceEPSS 1.1%CVE-2023-20863MEDIUMIn spring framework versions prior to 5.2.24 release+ ,5.3.27+ and 6.0.8+ , it is possible for a user to provide a specially crafted SpEL exEPSS 1.1%CVE-2023-40591HIGHDenial of service via malicious p2p message in go-ethereumEPSS 1.1%CVE-2022-21155HIGHFernhill SCADA Uncontrolled Resource ConsumptionEPSS 1.1%CVE-2023-28626MEDIUMQuadratic runtime when parsing Markdown in comrakEPSS 1.1%CVE-2024-20962MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 aEPSS 1.1%CVE-2023-23447HIGHUncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 112252EPSS 1.1%CVE-2023-43646HIGHInefficient Regular Expression Complexity in get-func-nameEPSS 1.1%