Fallos del tipo CWE-400

3026 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2022-1468MEDIUMOn all versions of 17.0.x, 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x on F5 BIG-IP, an authenticated iControl REST user with at leasEPSS 0.9%CVE-2024-38809MEDIUMApplications that parse ETags from "If-Match" or "If-None-Match" request headers are vulnerable to DoS attack. Users of affected versions sEPSS 0.9%CVE-2021-22642HIGHOvarro TBox Uncontrolled Resource ConsumptionEPSS 0.9%CVE-2021-3912MEDIUMOctoRPKI crashes when processing GZIP bomb returned via malicious repositoryEPSS 0.9%CVE-2024-20996MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.37 and prior anEPSS 0.9%CVE-2024-21142MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected aEPSS 0.9%CVE-2024-23259MEDIUMThe issue was addressed with improved checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14EPSS 0.9%CVE-2024-21127MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.37 and priEPSS 0.9%CVE-2026-40983HIGHMicrometer gRPC server instrumentation DoS vulnerabilityEPSS 0.8%CVE-2026-44250HIGHNetty: Memory Exhaustion in RedisArrayAggregator due to Deeply Nested ArraysEPSS 0.8%CVE-2026-50011HIGHNetty has unbounded pre-allocation in RedisArrayAggregator from RESP array lengthEPSS 0.8%CVE-2026-44890HIGHNetty has Unbounded Direct Memory Consumption in its RedisDecoderEPSS 0.8%CVE-2018-0471—Cisco IOS XE Software Cisco Discovery Protocol Memory Leak VulnerabilityEPSS 0.8%CVE-2026-54772HIGHCoreWCF: Pre-authentication infinite-loop CPU exhaustion in CoreWCF net.tcp / net.pipe / net.uds framing handshakeEPSS 0.8%CVE-2022-43564MEDIUMDenial of Service in Splunk Enterprise through search macrosEPSS 0.8%CVE-2024-5013HIGHWhatsUp Gold InstallController Denial-of-Service VulnerabilityEPSS 0.8%CVE-2026-42579HIGHNetty: DNS Codec Input Validation Bypass in Netty (Encoder + Decoder)EPSS 0.8%CVE-2024-32972HIGHgo-ethereum denial of service via malicious p2p messageEPSS 0.8%CVE-2024-49129HIGHWindows Remote Desktop Gateway (RD Gateway) Denial of Service VulnerabilityEPSS 0.8%CVE-2020-9059—Z-Wave devices based on Silicon Labs 500 series chipsets using S0 authentication are susceptible to uncontrolled resource consumption leadinEPSS 0.8%