Fallos del tipo CWE-400

3026 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2022-33168HIGHIBM Security Directory Suite VA denial of serviceEPSS 0.8%CVE-2026-48834HIGHApache Answer: Denial of service via crafted Accept-Language header parsingEPSS 0.8%CVE-2023-6193MEDIUMUnbounded queuing of path validation messages in cloudflare-quicheEPSS 0.8%CVE-2024-7771MEDIUMDenial of Service in mintplex-labs/anything-llmEPSS 0.8%CVE-2026-57576MEDIUMplone.app.dexterity and plone.app.contenttypes have a Denial of Service due to excessive title or description lengthEPSS 0.8%CVE-2023-35909MEDIUMWordPress Ninja Forms Plugin <= 3.6.25 is vulnerable to Denial of Service AttackEPSS 0.8%CVE-2024-32984HIGHYamux Memory Exhaustion Vulnerability via Active::pending_frames property EPSS 0.8%CVE-2026-54135HIGHAirSane has a Remote Denial of Service (OOM) via Unvalidated Content-Length in HTTP ServerEPSS 0.8%CVE-2024-21177MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.37 aEPSS 0.8%CVE-2023-46361—Artifex Software jbig2dec v0.20 was discovered to contain a SEGV vulnerability via jbig2_error at /jbig2dec/jbig2.c.EPSS 0.8%CVE-2026-67872HIGHAn issue in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the event monitored-item queue resize handlingEPSS 0.8%CVE-2024-21232LOWVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services). Supported versions that are affected arEPSS 0.8%CVE-2026-67856HIGHAn issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via crafted CreateSubscription, CreateMonitorEPSS 0.8%CVE-2026-31052MEDIUMAn issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to cause a denial of service via the Checkout Authentication Flow EPSS 0.8%CVE-2026-67864HIGHAn issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the NodeManagement type-instantiation logEPSS 0.8%CVE-2023-49550HIGHAn issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs+0x4ec508 component.EPSS 0.8%CVE-2023-27567—In OpenBSD 7.2, a TCP packet with destination port 0 that matches a pf divert-to rule can crash the kernel.EPSS 0.8%CVE-2026-26018HIGHCoreDNS Loop Detection Denial of Service VulnerabilityEPSS 0.8%CVE-2023-3825HIGH PTC’s KEPServerEX Versions 6.0 to 6.14.263 are vulnerable to being made to read a recursively defined object that leads to uncontrolled resEPSS 0.8%CVE-2023-39748—An issue in the component /userRpm/NetworkCfgRpm of TP-Link TL-WR1041N V2 allows attackers to cause a Denial of Service (DoS) via a crafted EPSS 0.8%