Fallos del tipo CWE-400

3026 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2023-4486HIGHUncontrolled Resource Consumption in Metasys and Facility ExplorerEPSS 0.8%CVE-2024-20344MEDIUMA vulnerability in system resource management in Cisco UCS 6400 and 6500 Series Fabric Interconnects that are in Intersight Managed Mode (IMEPSS 0.8%CVE-2026-27630HIGHTinyWeb vulnerable to Remote Denial of Service via Thread/Connection Exhaustion (Slowloris)EPSS 0.8%CVE-2026-42006MEDIUMAn attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomplete, only blocking onEPSS 0.8%CVE-2026-92596HIGHNodemailer before 9.1.0 Denial of Service via addressparserEPSS 0.8%CVE-2026-27633HIGHTinyWeb has Unbounded Content-Length Memory Exhaustion (DoS)EPSS 0.8%CVE-2026-47073HIGHUnbounded memory consumption in WebSocket client in hackneyEPSS 0.8%CVE-2025-5024HIGHGnome-remote-desktop: uncontrolled resource consumption due to malformed rdp pdusEPSS 0.8%CVE-2024-12074MEDIUMDenial of Service in automatic1111/stable-diffusion-webuiEPSS 0.8%CVE-2025-53012MEDIUMMaterialX's Lack of Import Depth Limit Leads to DoS (Denial-Of-Service) Via Stack ExhaustionEPSS 0.8%CVE-2024-21173MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.37 and prior anEPSS 0.8%CVE-2024-21130MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.37 aEPSS 0.8%CVE-2026-25949HIGHTraefik: TCP readTimeout bypass via STARTTLS on PostgresEPSS 0.8%CVE-2024-9409HIGHCWE-400: An Uncontrolled Resource Consumption vulnerability exists that could cause the device to become unresponsive resulting in communicaEPSS 0.8%CVE-2022-43572HIGHIndexing blockage via malformed data sent through S2S or HEC protocols in Splunk EnterpriseEPSS 0.8%CVE-2023-41173—AdGuard DNS before 2.2 allows remote attackers to cause a denial of service via malformed UDP packets.EPSS 0.8%CVE-2020-1625MEDIUMJunos OS: Kernel memory leak in virtual-memory due to interface flapsEPSS 0.8%CVE-2024-10466HIGHBy sending a specially crafted push message, a remote server could have hung the parent process, causing the browser to become unresponsive.EPSS 0.8%CVE-2026-79651HIGHKeycloak-services: keycloak-services: unauthenticated dos via unbounded locale cachingEPSS 0.8%CVE-2026-27857MEDIUMSending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands will result in client EPSS 0.8%