Fallos del tipo CWE-400

3026 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2019-10972—Mitsubishi Electric FR Configurator2, Version 1.16S and prior. This vulnerability can be triggered when an attacker provides the target withEPSS 0.9%CVE-2026-34282HIGHVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: NetworkEPSS 0.9%CVE-2023-24574HIGH Dell Enterprise SONiC OS, 3.5.3, 4.0.0, 4.0.1, 4.0.2, contains an "Uncontrolled Resource Consumption vulnerability" in authentication compoEPSS 0.9%CVE-2021-22955—A unauthenticated denial of service vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 when configured as a VPN (GatEPSS 0.9%CVE-2022-27182MEDIUMOn F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, and 14.1.x versions prior to 14.1.4.6, when BIG-IP packetEPSS 0.9%CVE-2026-56741HIGHJLine: Unauthenticated Remote DoS via Unbounded Telnet NAWS Terminal GeometryEPSS 0.9%CVE-2022-39330MEDIUMDatabase resource exhaustion for logged-in users via sharee recommendations with circlesEPSS 0.9%CVE-2022-23030—On version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and all versions of 13.1.x, when the BIG-IP Virtual EditionEPSS 0.9%CVE-2024-21207MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.38 and prior, 8EPSS 0.9%CVE-2023-34324MEDIUMPossible deadlock in Linux kernel event handlingEPSS 0.9%CVE-2024-21055MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 aEPSS 0.9%CVE-2023-50966MEDIUMerlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (EPSS 0.9%CVE-2022-4952LOWOmniSharp csharp-language-server-protocol JSON Serializer SerializerBase.cs CreateSerializerSettings resource consumptionEPSS 0.9%CVE-2022-2764—A flaw was found in Undertow. Denial of service can be achieved as Undertow server waits for the LAST_CHUNK forever for EJB invocations.EPSS 0.9%CVE-2022-41968LOWNextcloud Server's calendar name length not validated before writing to databaseEPSS 0.9%CVE-2026-56740HIGHJLine: Unauthenticated Remote Memory Exhaustion via Unbounded Telnet NEW-ENVIRON VariablesEPSS 0.9%CVE-2022-25622MEDIUMThe PROFINET (PNIO) stack, when integrated with the Interniche IP stack, improperly handles internal resources for TCP segments where the miEPSS 0.9%CVE-2023-6681MEDIUMJwcrypto: denail of service via specifically crafted jweEPSS 0.9%CVE-2024-21196MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: X Plugin). Supported versions that are affected are 8.0.39 anEPSS 0.9%CVE-2026-3505HIGHUnbounded PGP AEAD chunk size leads to pre-auth resource exhaustion.EPSS 0.9%