Fallos del tipo CWE-400

3026 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2022-28691HIGHOn F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prioEPSS 0.9%CVE-2024-28863MEDIUMnode-tar vulnerable to denial of service while parsing a tar file due to lack of folders count validationEPSS 0.9%CVE-2025-30715MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services). Supported versions that are affected arEPSS 0.9%CVE-2025-30705MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: PS). Supported versions that are affected are 8.0.0-8.0.41, 8EPSS 0.9%CVE-2024-21204MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: PS). Supported versions that are affected are 8.4.0 and 9.0.EPSS 0.9%CVE-2024-23835HIGHSuricata's pgsql: memory exhaustion use on record parsingEPSS 0.9%CVE-2024-20983MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.34 and priEPSS 0.9%CVE-2006-6025HIGHQUALCOMM Eudora WorldMail 4.0 allows remote attackers to cause a denial of service, as demonstrated by a certain module in VulnDisco Pack. EPSS 0.9%CVE-2022-36034HIGHPossible Regular Expression Denial of Service (ReDoS) used on uncontrolled data in nitrado.jsEPSS 0.9%CVE-2022-20854HIGHA vulnerability in the processing of SSH connections of Cisco Firepower Management Center (FMC) and Cisco Firepower Threat Defense (FTD) SofEPSS 0.9%CVE-2023-28507CRITICALMemory exhaustion in LZ4 decompression in UniRPC daemonEPSS 0.9%CVE-2021-32763MEDIUMRegular Expression Denial of Service in OpenProject forum messagesEPSS 0.9%CVE-2021-23053—On version 15.1.x before 15.1.3, 14.1.x before 14.1.3.1, and 13.1.x before 13.1.3.6, when the brute force protection feature of BIG-IP AdvanEPSS 0.9%CVE-2020-20813—Control Channel in OpenVPN 2.4.7 and earlier allows remote attackers to cause a denial of service via crafted reset packet.EPSS 0.9%CVE-2023-46442MEDIUMAn infinite loop in the retrieveActiveBody function of Soot before v4.4.1 under Java 8 allows attackers to cause a Denial of Service (DoS).EPSS 0.9%CVE-2026-25535HIGHjsPDF Affected by Client-Side/Server-Side Denial of Service via Malicious GIF DimensionsEPSS 0.9%CVE-2022-1337MEDIUMOOM DoS in Mattermost image proxyEPSS 0.9%CVE-2022-43780HIGHCertain HP ENVY, OfficeJet, and DeskJet printers may be vulnerable to a Denial of Service attack.EPSS 0.9%CVE-2022-27181MEDIUMOn F5 BIG-IP APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prEPSS 0.9%CVE-2022-29480MEDIUMOn F5 BIG-IP 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, when multiple route domains are configured, undisclosedEPSS 0.9%