Fallos del tipo CWE-400

3026 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2021-41546—A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.14.1), RUGGEDCOM ROX RX1400 (All versions < V2.14.1), RUGGEDCEPSS 1.0%CVE-2022-38100HIGHContec Health CMS8000EPSS 1.0%CVE-2023-25151HIGHDoS vulnerability for high cardinality metrics in opentelemetry-go-contribEPSS 1.0%CVE-2022-22161HIGHJunos OS: MX104 might become unresponsive if the out-of-band management port receives a flood of trafficEPSS 1.0%CVE-2023-41102HIGHAn issue was discovered in the captive portal in OpenNDS before version 10.1.3. It has multiple memory leaks due to not freeing up allocatedEPSS 1.0%CVE-2024-29893MEDIUMUncontrolled Resource Consumption vulnerability in ArgoCD's repo serverEPSS 1.0%CVE-2026-21945HIGHVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: SecuritEPSS 1.0%CVE-2023-20861—In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2.22.RELEASE, and older unsupported versions, it is possible fEPSS 1.0%CVE-2022-31075MEDIUMKubeEdge DoS when signing the CSR from EdgeCoreEPSS 1.0%CVE-2023-3398MEDIUMDenial of Service in jgraph/drawioEPSS 1.0%CVE-2024-21057MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 aEPSS 1.0%CVE-2026-44496HIGHAxios: Regular Expression Denial of Service (ReDoS) via Cookie Name InjectionEPSS 1.0%CVE-2018-15437MEDIUMCisco Immunet and Cisco AMP for Endpoints System Scan Denial of Service VulnerabilityEPSS 1.0%CVE-2026-33176MEDIUMRails Active Support has a possible DoS vulnerability in its number helpersEPSS 1.0%CVE-2024-28854HIGHSlow loris vulnerability with default configuration in tls-listenerEPSS 1.0%CVE-2021-0233HIGHJunos OS: ACX500 Series, ACX4000 Series: Denial of Service due to FFEB crash while processing high rate of specific packets.EPSS 1.0%CVE-2023-37475HIGHAttacker-controlled parameter can cause denial of service in hamba avroEPSS 1.0%CVE-2021-23049—On BIG-IP version 16.0.x before 16.0.1.2 and 15.1.x before 15.1.3, when the iRules RESOLVER::summarize command is used on a virtual server, EPSS 1.0%CVE-2021-0230HIGHJunos OS: SRX Series: Memory leak when querying Aggregated Ethernet (AE) interface statisticsEPSS 1.0%CVE-2021-3478—There's a flaw in OpenEXR's scanline input file functionality in versions before 3.0.0-beta. An attacker able to submit a crafted file to beEPSS 1.0%