Fallos del tipo CWE-400

3026 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2026-42587HIGHNetty: HttpContentDecompressor maxAllocation bypass via Content-Encoding: br/zstd/snappy enables decompression bomb DoSEPSS 1.0%CVE-2024-45166CRITICALAn issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Due to improper input validation, improper deserialization, and iEPSS 1.0%CVE-2020-7584—A vulnerability has been identified in SIMATIC S7-200 SMART CPU family (All versions >= V2.2 < V2.5.1). Affected devices do not properly hanEPSS 1.0%CVE-2024-52804HIGHTornado has HTTP cookie parsing DoS vulnerabilityEPSS 1.0%CVE-2020-5347MEDIUMDell EMC Isilon OneFS versions 8.2.2 and earlier contain a denial of service vulnerability. SmartConnect had an error condition that may be EPSS 1.0%CVE-2025-21352MEDIUMInternet Connection Sharing (ICS) Denial of Service VulnerabilityEPSS 1.0%CVE-2023-27321HIGHOPC Foundation UA .NET Standard ConditionRefresh Resource Exhaustion Denial-of-Service VulnerabilityEPSS 1.0%CVE-2024-20971MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 aEPSS 1.0%CVE-2026-27858HIGHAttacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. AttackeEPSS 1.0%CVE-2024-20981MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.35 and priEPSS 1.0%CVE-2021-25659—A vulnerability has been identified in Automation License Manager 5 (All versions), Automation License Manager 6 (All versions < V6.0 SP9 UpEPSS 1.0%CVE-2023-24824MEDIUMQuadratic complexity may lead to a denial of service in cmark-gfmEPSS 1.0%CVE-2022-45003HIGHGophish through 0.12.1 allows attackers to cause a Denial of Service (DoS) via a crafted payload involving autofocus.EPSS 1.0%CVE-2024-33774MEDIUMA buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via formWlanSetup_Wizard allows remote authenticated users to trEPSS 1.0%CVE-2024-21536HIGHVersions of the package http-proxy-middleware before 2.0.7, from 3.0.0 and before 3.0.3 are vulnerable to Denial of Service (DoS) due to an EPSS 1.0%CVE-2023-28846MEDIUMDenial of Service in unpoly-railsEPSS 1.0%CVE-2023-38741HIGHIBM TXSeries for Multiplatforms denial of serviceEPSS 1.0%CVE-2026-19446HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 1.0%CVE-2022-47934MEDIUMBrave Browser before 1.43.88 allowed a remote attacker to cause a denial of service in private and guest windows via a crafted HTML file thaEPSS 1.0%CVE-2024-20978MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 aEPSS 1.0%