Fallos del tipo CWE-400

3026 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2024-32269HIGHAn issue in Yonganda YAD-LOJ V3.0.561 allows a remote attacker to cause a denial of service via a crafted packet.EPSS 0.7%CVE-2025-46728HIGHcpp-httplib has Unbounded Memory Allocation in Chunked/No-Length RequestsEPSS 0.7%CVE-2026-27204MEDIUMWasmtime WASI implementations are vulnerable to guest-controlled resource exhaustionEPSS 0.7%CVE-2026-34829HIGHRack: Denial of Service via Unbounded Multipart File Upload Without Content-LengthEPSS 0.7%CVE-2020-15853MEDIUMsupybot-fedora implements the command 'refresh', that refreshes the cache of all users from FAS. This takes quite a while to run, and zodbotEPSS 0.7%CVE-2020-1903—An issue when unzipping docx, pptx, and xlsx documents in WhatsApp for iOS prior to v2.20.61 and WhatsApp Business for iOS prior to v2.20.61EPSS 0.7%CVE-2026-71314HIGHNuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island renderingEPSS 0.7%CVE-2026-34827HIGHRack: Algorithmic-Complexity DoS in Rack::Multipart::ParserEPSS 0.7%CVE-2024-21914MEDIUMRockwell Automation - FactoryTalk® View ME on PanelView™ Plus 7 Boot Terminal lack Security ProtectionsEPSS 0.7%CVE-2026-65819HIGHgopacket: Multiple layer decoders panic on crafted packets (out-of-bounds/underflow) enabling unauthenticated remote DoS via DecodingLayerParserEPSS 0.7%CVE-2023-42813MEDIUMDenial of service from malicious manifest in kyvernoEPSS 0.7%CVE-2024-3153MEDIUMUncontrolled Resource Consumption in mintplex-labs/anything-llmEPSS 0.7%CVE-2026-59200HIGHPillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()EPSS 0.7%CVE-2026-59161HIGHExcelize: Streaming GetRows row-bound bypass causes attacker-controlled allocationEPSS 0.7%CVE-2025-48795MEDIUMApache CXF: Denial of Service and sensitive data exposure in logsEPSS 0.7%CVE-2026-45357HIGHLiquidJS: Memory and render limit bypass via unbounded width padding in `date` filter (strftime)EPSS 0.7%CVE-2026-39320HIGHSignal K Server has an Unauthenticated Regular Expression Denial of Service (ReDoS) via WebSocket Subscription PathsEPSS 0.7%CVE-2026-25762HIGHAdonisJS vulnerable to Denial of Service (DoS) via Unrestricted Memory Buffering in PartHandler during File Type DetectionEPSS 0.7%CVE-2023-20176MEDIUMA vulnerability in the networking component of Cisco access point (AP) software could allow an unauthenticated, remote attacker to cause a tEPSS 0.7%CVE-2026-32588MEDIUMApache Cassandra: Authenticated DoS via ALTER ROLE Password HashingEPSS 0.7%