Fallos del tipo CWE-400

3026 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2022-22145—CAMS for HIS Log Server contained in the following Yokogawa Electric products is vulnerable to uncontrolled resource consumption. CENTUM CS EPSS 0.8%CVE-2023-49800HIGHDenial of service by abusing `fetchOptions.retry` in nuxt-api-partyEPSS 0.8%CVE-2023-5625MEDIUMPython-eventlet: patch regression for cve-2021-21419 in some red hat buildsEPSS 0.8%CVE-2026-42001HIGHInsufficient Validation of Autoprimary SOA QueriesEPSS 0.8%CVE-2016-10524—i18n-node-angular is a module used to interact between i18n and angular without using additional resources. A REST API endpoint that is usedEPSS 0.8%CVE-2026-42403HIGHApache Neethi: Circular Policy Reference Infinite LoopEPSS 0.8%CVE-2024-45626MEDIUMApache James: denial of service through JMAP HTML to text conversionEPSS 0.8%CVE-2022-31074MEDIUMKubeEdge Cloud AdmissionController component DoSEPSS 0.8%CVE-2023-23296MEDIUMKorenix JetWave 4200 Series 1.3.0 and JetWave 3200 Series 1.6.0 are vulnerable to Denial of Service via /goform/formDefault.EPSS 0.8%CVE-2023-27483MEDIUMfieldpath's Paved.SetValue allows growing arrays up to arbitrary sizes in crossplane-runtimeEPSS 0.8%CVE-2023-0384MEDIUMUncontrolled Resource Consuption in M-Files ServerEPSS 0.8%CVE-2022-23591HIGHStack overflow in TensorflowEPSS 0.8%CVE-2024-39895MEDIUMDirectus GraphQL Field Duplication Denial of Service (DoS)EPSS 0.8%CVE-2026-96541HIGHGnome-remote-desktop: gnome-remote-desktop: unauthenticated rdp sockets lack a handshake deadlineEPSS 0.8%CVE-2021-0215MEDIUMJunos OS: EX Series, QFX Series, SRX Branch Series, MX Series: Memory leak in packet forwarding engine due to 802.1X authenticator port interface flapsEPSS 0.8%CVE-2025-30704MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services). Supported versions that are affected arEPSS 0.8%CVE-2022-21653MEDIUMHash collision in typelevel jawnEPSS 0.8%CVE-2026-7790HIGHUnbounded chunk-size hex digits in cowlib cause quadratic CPU and memory DoSEPSS 0.8%CVE-2021-38463HIGHAUVESY VersiondogEPSS 0.8%CVE-2026-73507HIGHNetty: Denial of Service in XmlFrameDecoder via CPU ExhaustionEPSS 0.8%