Fallos del tipo CWE-400

3026 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2026-49485HIGHHAPI FHIR: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP EndpointEPSS 0.7%CVE-2026-37459HIGHAn integer underflow in FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a craftEPSS 0.7%CVE-2022-46352HIGHA vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALAEPSS 0.7%CVE-2025-0704MEDIUMJoeyBling bootplus QrCodeController.java qrCode resource consumptionEPSS 0.7%CVE-2024-42943HIGHTenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the PPPOEPassword parameter in the fromAdvSetWan function. This EPSS 0.7%CVE-2024-34483HIGHOFPGroupDescStats in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via OFPBucket.len=0.EPSS 0.7%CVE-2024-24988MEDIUMExcessive resource consumption when sending long emoji names in user custom statusEPSS 0.7%CVE-2023-26044MEDIUMReactPHP's HTTP server continues parsing unused multipart parts after reaching limitsEPSS 0.7%CVE-2023-23616LOWDiscourse membership requests lack character limitEPSS 0.7%CVE-2022-4767HIGHDenial of Service in usememos/memosEPSS 0.7%CVE-2023-2831MEDIUMDenial of Service while unescaping a Markdown stringEPSS 0.7%CVE-2023-27484MEDIUMUnchecked fieldpath index in Composition's patches can lead to arbitrary memory allocation in crossplaneEPSS 0.7%CVE-2023-50020HIGHAn issue was discovered in open5gs v2.6.6. SIGPIPE can be used to crash AMF.EPSS 0.7%CVE-2023-23625MEDIUMDenial of service in HAMT Decoding in go-unixfs EPSS 0.7%CVE-2021-26945—An integer overflow leading to a heap-buffer overflow was found in OpenEXR in versions before 3.0.1. An attacker could use this flaw to crasEPSS 0.7%CVE-2019-5043MEDIUMAn exploitable denial-of-service vulnerability exists in the Weave daemon of the Nest Cam IQ Indoor, version 4620002. A set of TCP connectioEPSS 0.7%CVE-2026-59902HIGHNetty: Memory Exhaustion in SctpMessageCompletionHandlerEPSS 0.7%CVE-2024-4599HIGHDenial of service vulnerability in LAN MessengerEPSS 0.7%CVE-2023-38251MEDIUMAdobe Commerce | Uncontrolled Resource Consumption (CWE-400)EPSS 0.7%CVE-2026-58483HIGHmcp-searxng: Unbounded Response Body Read Bypasses URL Size Limit in `web_url_read`EPSS 0.7%