Fallos del tipo CWE-400

3026 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2022-46399HIGHThe Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) is unresponsive with ConReqTimeoutZerEPSS 0.7%CVE-2022-33203HIGHBIG-IP APM and F5 SSL Orchestrator vulnerability CVE-2022-33203EPSS 0.7%CVE-2024-25398HIGHIn Srelay (the SOCKS proxy and Relay) v.0.4.8p3, a specially crafted network payload can trigger a denial of service condition and disrupt tEPSS 0.7%CVE-2022-35236HIGHHTTP2 profile vulnerability CVE-2022-35236EPSS 0.7%CVE-2025-8262MEDIUMyarnpkg Yarn hosted-git-resolver.js explodeHostedGitFragment redosEPSS 0.7%CVE-2019-0038MEDIUMSRX Series: Crafted packets destined to fxp0 management interface on SRX340/SRX345 devices can lead to DoSEPSS 0.7%CVE-2025-49763HIGHApache Traffic Server: Remote DoS via memory exhaustion in ESI PluginEPSS 0.7%CVE-2025-4215LOWgorhill uBlock Origin UI 1p-filters.js currentStateChanged redosEPSS 0.7%CVE-2026-58210HIGHNATS Server: MQTT partial CONNECT packets can exhaust pre-auth memoryEPSS 0.7%CVE-2020-26652—An issue was discovered in function nl80211_send_chandef in rtl8812au v5.6.4.2 allows attackers to cause a denial of service.EPSS 0.7%CVE-2026-6607MEDIUMlm-sys fastchat Worker API Endpoint api_generate resource consumptionEPSS 0.7%CVE-2026-66144HIGHApache Neethi: Remote PolicyReference fetch lacks resource boundsEPSS 0.7%CVE-2026-50645HIGHApache CXF: No restriction on attachment headers per messageEPSS 0.7%CVE-2026-66142HIGHApache Neethi: Uncontrolled recursion in policy processingEPSS 0.7%CVE-2026-59173HIGHApache Traffic Server: DoS vulnerability in HTTP/2 via stalled flow-control conditionsEPSS 0.7%CVE-2026-66299HIGHApache Tomcat: DoS via WebSocket chat exampleEPSS 0.7%CVE-2026-42402HIGHApache Neethi: Policy Normalization Unbounded Resource Allocation DoSEPSS 0.7%CVE-2026-24012HIGHApache IoTDB: Denial of Service via Resource Exhaustion in Aggregation QueryEPSS 0.7%CVE-2022-28229HIGHThe hash functionality in userver before 42059b6319661583b3080cab9b595d4f8ac48128 allows attackers to cause a denial of service via crafted EPSS 0.7%CVE-2024-57519HIGHAn issue in Open5GS v.2.7.2 allows a remote attacker to cause a denial of service via the ogs_dbi_auth_info function in lib/dbi/subscriptionEPSS 0.7%