Fallos del tipo CWE-400

3026 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2022-41806HIGHBIG-IP AFM NAT64 Policy Vulnerability CVE-2022-41806EPSS 0.7%CVE-2026-58483HIGHmcp-searxng: Unbounded Response Body Read Bypasses URL Size Limit in `web_url_read`EPSS 0.7%CVE-2022-41833HIGHBIG-IP iRule vulnerability CVE-2022-41833EPSS 0.7%CVE-2024-29186MEDIUMSlow String Operations via MultiPart Requests in Event-Driven FunctionsEPSS 0.7%CVE-2023-43775MEDIUMSecurity issue in SMP Gateway automation platformEPSS 0.7%CVE-2026-1605HIGHIn Eclipse Jetty, versions 12.0.0-12.0.31 and 12.1.0-12.0.5, class GzipHandler exposes a vulnerability when a compressed HTTP request, with EPSS 0.7%CVE-2019-0046MEDIUMJunos OS: EX4300 Series: Denial of Service upon receipt of large number of specific valid packets on management interface.EPSS 0.7%CVE-2026-55833HIGHNetty SPDY zlib header block continues decoded expansion after maxHeaderSize truncationEPSS 0.7%CVE-2024-5422HIGHDenial of ServiceEPSS 0.7%CVE-2026-34148HIGHFedify affected by resource exhaustion caused by unbounded redirect following during remote key/document resolutionEPSS 0.7%CVE-2026-56819HIGHNetty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS)EPSS 0.7%CVE-2026-55831HIGHNetty SPDY SETTINGS frame count materializes unbounded settings mapEPSS 0.7%CVE-2026-59879HIGHImmutable.js `List` 32-bit trie overflow → unrecoverable DoSEPSS 0.7%CVE-2024-25718CRITICALIn the Samly package before 1.4.0 for Elixir, Samly.State.Store.get_assertion/3 can return an expired session, which interferes with access EPSS 0.7%CVE-2026-58151HIGHApache Traffic Server: Abusive HTTP/2 framing can exhaust resources and crash the serverEPSS 0.7%CVE-2026-65324HIGHApache Traffic Server: HTTP/2 and HTTP/3 dechunking removes per-stream buffer cap, allowing memory exhaustionEPSS 0.7%CVE-2026-64958HIGHApache CXF: Denial of service via message header attachmentsEPSS 0.7%CVE-2023-22470LOWNextcloud Deck vulnerable to uncontrolled resource consumption EPSS 0.7%CVE-2026-41309HIGHOpen Source Social Network (OSSN) Vulnerable to Resource Exhaustion via Malicious Image ProcessingEPSS 0.7%CVE-2024-32269HIGHAn issue in Yonganda YAD-LOJ V3.0.561 allows a remote attacker to cause a denial of service via a crafted packet.EPSS 0.7%