Fallos del tipo CWE-400

3026 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2026-5316MEDIUMNothings stb stb_vorbis.c setup_free allocation of resourcesEPSS 0.7%CVE-2025-2833MEDIUMzhangyd-c OneBlog HTTP Header redosEPSS 0.7%CVE-2024-1014MEDIUMUncontrolled resource consumption vulnerability in SE-elektronic GmbH E-DDC3.3EPSS 0.7%CVE-2024-23265CRITICALA memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPaEPSS 0.7%CVE-2022-3818MEDIUMAn uncontrolled resource consumption issue when parsing URLs in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, aEPSS 0.7%CVE-2022-3510HIGHParsing issue in protobuf message-type extensionEPSS 0.7%CVE-2022-34335MEDIUMIBM Sterling Partner Engagement Manager denial of serviceEPSS 0.7%CVE-2025-47270HIGHnimiq-network-libp2p Uncontrolled Resource Consumption vulnerabilityEPSS 0.7%CVE-2024-20321HIGHA vulnerability in the External Border Gateway Protocol (eBGP) implementation of Cisco NX-OS Software could allow an unauthenticated, remoteEPSS 0.7%CVE-2022-23486HIGHlibp2p-rust denial of service vulnerability from lack of resource managementEPSS 0.7%CVE-2026-55685HIGHReact Router: Unauthenticated Denial of Service via Inefficient Route MatchingEPSS 0.7%CVE-2022-23487HIGHlibp2p denial of service vulnerability from lack of resource managementEPSS 0.7%CVE-2026-45031MEDIUMImageMagick: Policy Bypass in PSD decoderEPSS 0.7%CVE-2026-61554HIGHemp3r0r has an unauthenticated HTTP Polling DoSEPSS 0.7%CVE-2024-11043HIGHDenial of Service (DoS) via Large Payload in Board Name Field in invoke-ai/invokeaiEPSS 0.7%CVE-2024-12761HIGHDenial of Service in brycedrennan/imaginairyEPSS 0.7%CVE-2023-37481LOWFides Webserver Vulnerable to SVG Bomb File UploadsEPSS 0.7%CVE-2024-27874HIGHThis issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS 18. A remote attacker may be able to caEPSS 0.7%CVE-2022-31079MEDIUMKubeEdge Cloud Stream and Edge Stream DoS from large stream messageEPSS 0.7%CVE-2022-31078MEDIUMKubeEdge CloudCore Router memory exhaustionEPSS 0.7%