Fallos del tipo CWE-400

3026 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2023-48951HIGHAn issue in the box_equal function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) after runningEPSS 0.8%CVE-2024-9358MEDIUMThingsBoard HTTP RPC API resource consumptionEPSS 0.8%CVE-2024-43380MEDIUMfugit parse and parse_nat stall on lengthy inputEPSS 0.8%CVE-2023-6596HIGHOpenshift: incomplete fix for rapid reset (cve-2023-44487/cve-2023-39325)EPSS 0.8%CVE-2024-4438HIGHEtcd: incomplete fix for cve-2023-39325/cve-2023-44487 in openstack platformEPSS 0.8%CVE-2021-41168MEDIUMHash-Collision Denial-of-Service Vulnerability in snudownEPSS 0.8%CVE-2024-22362HIGHDrupal contains a vulnerability with improper handling of structural elements. If this vulnerability is exploited, an attacker may be able tEPSS 0.8%CVE-2024-52520MEDIUMNextcloud Server's link reference provider can be tricked into downloading bigger files than intendedEPSS 0.8%CVE-2026-12151HIGHundici WebSocket client vulnerable to denial of service via fragment count bypassEPSS 0.8%CVE-2025-6365MEDIUMHobbesOSR Kitten pgtable.h set_pte_at resource consumptionEPSS 0.8%CVE-2023-41706MEDIUMProcessing time of drive search expressions now gets monitored, and the related request is terminated if a resource threshold is reached. AvEPSS 0.8%CVE-2023-41707MEDIUMProcessing of user-defined mail search expressions is not limited. Availability of OX App Suite could be reduced due to high processing loadEPSS 0.8%CVE-2023-41705MEDIUMProcessing of user-defined DAV user-agent strings is not limited. Availability of OX App Suite could be reduced due to high processing load.EPSS 0.8%CVE-2023-50249HIGHSentry's Astro SDK vulnerable to ReDoSEPSS 0.8%CVE-2026-49289HIGHSimpleSAMLphp SAML2: Possible DoS via XPath TransformEPSS 0.8%CVE-2026-28342HIGHOliveTin: Unauthenticated Denial of Service via Memory Exhaustion in PasswordHash API EndpointEPSS 0.8%CVE-2024-33664MEDIUMpython-jose through 3.3.0 allows attackers to cause a denial of service (resource consumption) during a decode via a crafted JSON Web EncrypEPSS 0.8%CVE-2024-1569MEDIUMUncontrolled Resource Consumption in parisneo/lollms-webuiEPSS 0.8%CVE-2022-23524MEDIUMHelm vulnerable to Denial of service through string value parsingEPSS 0.8%CVE-2023-37014HIGHOpen5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An EPSS 0.8%