Fallos del tipo CWE-400

3026 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2022-39294HIGH(DoS) Denial of Service from unchecked request length in conduit-hyperEPSS 0.7%CVE-2021-36395HIGHIn Moodle, the file repository's URL parsing required additional recursion handling to mitigate the risk of recursion denial of service.EPSS 0.7%CVE-2026-57819HIGHApache CXF: No default restriction on the amount of form parameters per messageEPSS 0.7%CVE-2026-33610MEDIUMPossible file descriptor exhaustion in forward-dnsupdateEPSS 0.7%CVE-2021-3908MEDIUMInfinite certificate chain depth results in OctoRPKI running foreverEPSS 0.7%CVE-2024-20351HIGHCisco Firepower Threat Defense Software Snort Firewall Denial of Service VulnerabilityEPSS 0.7%CVE-2026-58182HIGHApache Traffic Server: ts_lua plugin has initialization and resource-handling errorsEPSS 0.7%CVE-2022-42929MEDIUMIf a website called `window.print()` in a particular way, it could cause a denial of service of the browser, which may persist beyond browseEPSS 0.7%CVE-2026-73634HIGHApache Struts: Unbounded read of a Content Security Policy violation reportEPSS 0.7%CVE-2024-11033MEDIUMDenial of Service (DoS) in binary-husky/gpt_academicEPSS 0.7%CVE-2023-49290MEDIUMMalicious parameters can cause a denial of service in lestrrat-go/jwxEPSS 0.7%CVE-2026-8769MEDIUMvercel ai provider-utils response-handler.ts createJsonErrorResponseHandler resource consumptionEPSS 0.7%CVE-2026-44891HIGHNetty: Denial of Service via Unbounded Headers in StompSubframeDecoderEPSS 0.7%CVE-2023-25774HIGHA denial-of-service vulnerability exists in the vpnserver ConnectionAccept() functionality of SoftEther VPN 5.02. A set of specially craftedEPSS 0.7%CVE-2026-34045HIGHPodman Desktop WebView Server ExposedEPSS 0.7%CVE-2026-59843MEDIUMLibssh: libssh: denial of service via zero advertised channel packet sizeEPSS 0.7%CVE-2024-38828MEDIUMCVE-2024-38828: DoS via Spring MVC controller method with byte[] parameterEPSS 0.7%CVE-2026-90584MEDIUMTooTallNate Java-WebSocket Fragmentation Draft_6455.java processFrameContinuousAndNonFin allocation of resourcesEPSS 0.7%CVE-2026-92114MEDIUMa2ui-project a2ui Basic Catalog safe_regex.ts redosEPSS 0.7%CVE-2023-40703MEDIUMDenial of Service via specially crafted block fields in Mattermost BoardsEPSS 0.7%