Fallos del tipo CWE-400

3026 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2024-6838MEDIUMUncontrolled Resource Consumption in mlflow/mlflowEPSS 0.7%CVE-2026-4671HIGHjusthtml before 1.18.0 Denial of Service via CSS SelectorEPSS 0.7%CVE-2023-36161—An issue was discovered in Qubo Smart Plug 10A version HSP02_01_01_14_SYSTEM-10A, allows attackers to cause a denial of service (DoS) via WiEPSS 0.7%CVE-2024-55605HIGHSuricata allows stack overflow in transformsEPSS 0.7%CVE-2026-30998HIGHAn improper resource deallocation and closure vulnerability in the tools/zmqsend.c component of FFmpeg v8.0.1 allows attackers to cause a DeEPSS 0.7%CVE-2024-38616HIGHwifi: carl9170: re-fix fortified-memset warningEPSS 0.7%CVE-2023-45847MEDIUM Playbook Plugin Crash via Run ChecklistEPSS 0.6%CVE-2026-78551HIGHRansomLook Login Endpoint Allows Timing-Based Username Enumeration and Unthrottled Authentication AttemptsEPSS 0.6%CVE-2024-52979MEDIUMElasticsearch Uncontrolled Resource Consumption vulnerabilityEPSS 0.6%CVE-2025-61919HIGHRack is vulnerable to a memory-exhaustion DoS through unbounded URL-encoded body parsingEPSS 0.6%CVE-2026-40140HIGHHigh-Severity Pre-Authentication Vulnerability in BeyondTrust Remote Support and Privileged Remote AccessEPSS 0.6%CVE-2026-69152HIGHbrace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigationEPSS 0.6%CVE-2022-41770MEDIUMBIG-IP and BIG-IQ iControl REST vulnerability CVE-2022-41770EPSS 0.6%CVE-2026-56816HIGHNetty: Memory Exhaustion via HTTP/3 Reserved Frame TypesEPSS 0.6%CVE-2026-49293HIGHCPU exhaustion via O(n^2) BigInt construction on radix-prefixed integer literalsEPSS 0.6%CVE-2026-59941MEDIUMDompdf: Uncontrolled resource consumption based on declared BMP dimensionsEPSS 0.6%CVE-2022-20691MEDIUMA vulnerability in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Adaptive Telephone Adapter firmware could allow an unaEPSS 0.6%CVE-2026-49476HIGHSoup Sieve: Memory Exhaustion via Large Comma-Separated Selector Lists in soupsieveEPSS 0.6%CVE-2021-32821MEDIUMRegular expression Denial of Service in MooToolsEPSS 0.6%CVE-2026-49477HIGHSoup Sieve: Regular Expression Denial of Service (ReDoS) in soupsieve Selector ParserEPSS 0.6%