Fallos del tipo CWE-400

3026 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2023-40703MEDIUMDenial of Service via specially crafted block fields in Mattermost BoardsEPSS 0.7%CVE-2022-31080MEDIUMKubeEdge Websocket Client in package Viaduct: DoS from large response messageEPSS 0.7%CVE-2025-0187HIGHDenial of Service (DoS) by Sending Large Filename at File Upload Endpoint in gradio-app/gradioEPSS 0.7%CVE-2023-40586HIGHgo package github.com/corazawaf/coraza is vulnerable to denial of serviceEPSS 0.7%CVE-2023-48268MEDIUMDenial of Service via Board Import Zip BombEPSS 0.7%CVE-2023-46131MEDIUMGrails® data binding causes JVM crash and/or DoS EPSS 0.7%CVE-2025-21614HIGHgo-git clients vulnerable to DoS via maliciously crafted Git server repliesEPSS 0.7%CVE-2021-22906—Nextcloud End-to-End Encryption before 1.5.3, 1.6.3 and 1.7.1 suffers from a denial of service vulnerability due to permitting any authenticEPSS 0.7%CVE-2023-3782MEDIUMDoS of the OkHttp client when using a BrotliInterceptor and surfing to a malicious web server, or when an attacker can perform MitM to inject a Brotli zip-bomb into an HTTP responseEPSS 0.7%CVE-2022-35241MEDIUMNGINX Instance Manager vulnerability CVE-2022-35241EPSS 0.7%CVE-2025-70327CRITICALTOTOLINK X5000R v9.1.0cu_2415_B20250515 contains an argument injection vulnerability in the setDiagnosisCfg handler of the /usr/sbin/lighttpEPSS 0.7%CVE-2026-44241HIGHMicronaut Framework: Unbounded formattersCache in TimeConverterRegistrar Allows Memory Exhaustion via Accept-Language HeaderEPSS 0.7%CVE-2025-4533MEDIUMJeecgBoot Document Library Upload zip unzipFile resource consumptionEPSS 0.7%CVE-2026-63448MEDIUMSuricata smb: some SMB flows can cause resource exhaustionEPSS 0.7%CVE-2023-28356HIGHA vulnerability has been identified where a maliciously crafted message containing a specific chain of characters can cause the chat to enteEPSS 0.7%CVE-2022-45044MEDIUMA vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V9.50), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 EPSS 0.7%CVE-2024-24781HIGHHima: Uncontrolled Resource Consumption in multiple productsEPSS 0.7%CVE-2024-31992MEDIUMMealie contains a DoS vulnerability in recipe importerEPSS 0.7%CVE-2026-5316MEDIUMNothings stb stb_vorbis.c setup_free allocation of resourcesEPSS 0.7%CVE-2026-46273HIGHibmveth: Disable GSO for packets with small MSSEPSS 0.7%