Fallos del tipo CWE-400

3026 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2026-73633HIGHApache Struts: Unbounded read of a JSON request bodyEPSS 0.7%CVE-2023-38498MEDIUMDiscourse vulnerable to DoS via defer queueEPSS 0.7%CVE-2026-84553HIGHA resource exhaustion issue was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, mEPSS 0.7%CVE-2023-37463MEDIUMQuadratic complexity bugs may lead to a denial of serviceEPSS 0.7%CVE-2026-25771MEDIUMWazuh Vulnerable to Denial of Service via Synchronous I/O Blocking in Asynchronous Authentication MiddlewareEPSS 0.7%CVE-2020-15101LOWNested directory structure can lead to Uncontrolled Resource Consumption in freewvsEPSS 0.7%CVE-2024-23744HIGHAn issue was discovered in Mbed TLS 3.5.1. There is persistent handshake denial if a client sends a TLS 1.3 ClientHello without extensions.EPSS 0.7%CVE-2021-43933MEDIUMICSA-22-109-03 FANUC ROBOGUIDE Simulation PlatformEPSS 0.7%CVE-2023-29153MEDIUMUncontrolled resource consumption for some Intel(R) SPS firmware before version SPS_E5_06.01.04.002.0 may allow a privileged user to potentiEPSS 0.7%CVE-2026-4410MEDIUMIBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a denial of serviceEPSS 0.7%CVE-2025-59043HIGHOpenBao vulnerable to denial of service via malicious JSON request processingEPSS 0.7%CVE-2020-1702—A malicious container image can consume an unbounded amount of memory when being pulled to a container runtime host, such as Red Hat EnterprEPSS 0.7%CVE-2023-28440LOWDenial of service via admin theme import route in DiscourseEPSS 0.7%CVE-2026-47707MEDIUMStrawberry GraphQL's Bypass of MaxAliasesLimiter via Fragment Spreads leading to GraphQL Alias AmplificationEPSS 0.7%CVE-2024-25269HIGHlibheif <= 1.17.6 contains a memory leak in the function JpegEncoder::Encode. This flaw allows an attacker to cause a denial of service attaEPSS 0.7%CVE-2025-29907HIGHjsPDF Bypass Regular Expression Denial of Service (ReDoS)EPSS 0.7%CVE-2026-50750HIGHApache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: Pre-authentication OpenWire DoS following fix for CVE-2026-49270EPSS 0.7%CVE-2023-37480LOWFides Webserver Vulnerable to Zip Bomb File UploadsEPSS 0.7%CVE-2023-43810HIGHopentelemetry-instrumentation Denial of Service vulnerability due to unbound cardinality metricsEPSS 0.7%CVE-2025-53114HIGHCometD has acknowledgement extension out of memoryEPSS 0.7%