Fallos del tipo CWE-400

3026 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2023-28837MEDIUMWagtail vulnerable to denial-of-service via memory exhaustion when uploading large filesEPSS 1.1%CVE-2022-23471MEDIUMcontainerd CRI stream server: Host memory exhaustion through terminal resize goroutine leakEPSS 1.1%CVE-2025-21529MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions that are affected areEPSS 1.1%CVE-2022-3277MEDIUMAn uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of seEPSS 1.1%CVE-2026-40984HIGHMicrometer HTTP server instrumentations DoS vulnerabilityEPSS 1.1%CVE-2026-39304HIGHApache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Incorrect handling of TLSv1.3 KeyUpdate can be exploited to cause DoS via OOMEPSS 1.1%CVE-2025-59502HIGHRemote Procedure Call Denial of Service VulnerabilityEPSS 1.1%CVE-2023-46120MEDIUMRabbitMQ Java client's lack of message size limitation leads to remote DoS attackEPSS 1.1%CVE-2025-5342MEDIUMDenial of Service (DoS)EPSS 1.1%CVE-2020-1684HIGHJunos OS: SRX Series: High CPU load due to processing for HTTP traffic when Application Identification is enabled.EPSS 1.1%CVE-2024-20977MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 aEPSS 1.1%CVE-2019-3554—Wangle's AcceptRoutingHandler incorrectly casts a socket when accepting a TLS 1.3 connection, leading to a potential denial of service attacEPSS 1.1%CVE-2023-48834HIGHA lack of rate limiting in pjActionAjaxSend in Car Rental v3.0 allows attackers to cause resource exhaustion.EPSS 1.1%CVE-2024-0348MEDIUMSourceCodester Engineers Online Portal File Upload resource consumptionEPSS 1.1%CVE-2025-21574MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 8.0.0-8.0.4EPSS 1.1%CVE-2023-22799—A ReDoS based DoS vulnerability in the GlobalID <1.0.1 which could allow an attacker supplying a carefully crafted input can cause the regulEPSS 1.0%CVE-2006-5708HIGHMultiple unspecified vulnerabilities in MDaemon and WorldClient in Alt-N Technologies MDaemon before 9.50 allow attackers to cause a denial EPSS 1.0%CVE-2024-22233HIGHCVE-2024-22233: Spring Framework server Web DoS VulnerabilityEPSS 1.0%CVE-2022-47932MEDIUMBrave Browser before 1.43.34 allowed a remote attacker to cause a denial of service via a crafted HTML file that mentions an ipfs:// or ipnsEPSS 1.0%CVE-2022-36055MEDIUMDenial of service in HelmEPSS 1.0%