Fallos del tipo CWE-400

3026 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2026-8319MEDIUMaiwaves-cn agents cheshire_cat_core stray_cat.py recall_relevant_memories_to_working_memory resource consumptionEPSS 0.6%CVE-2026-84857MEDIUMsigoden aichat API Endpoint serve.rs memory allocationEPSS 0.6%CVE-2026-5986MEDIUMZod jsVideoUrlParser util.js getTime redosEPSS 0.6%CVE-2026-84886MEDIUMsimular-ai Agent-S OCR HTTP API ocr_server.py ImageData resource consumptionEPSS 0.6%CVE-2023-34397HIGHMercedes Benz head-unit NTG 6 contains functions to import or export profile settings over USB. During parsing you can trigger that the servEPSS 0.6%CVE-2026-70646HIGHaiosend: Deserialization of request body before signature verification (Pre-auth DoS) in webhook handlerEPSS 0.6%CVE-2023-50019MEDIUMAn issue was discovered in open5gs v2.6.6. InitialUEMessage, Registration request sent at a specific time can crash AMF due to incorrect errEPSS 0.6%CVE-2023-26597HIGHController DOS on sending error responseEPSS 0.6%CVE-2026-67437HIGHOliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)EPSS 0.6%CVE-2024-21651HIGHXWiki Denial of Service attack through attachmentsEPSS 0.6%CVE-2023-37263MEDIUMStrapi's field level permissions not being respected in relationship titleEPSS 0.6%CVE-2023-43767—Certain WithSecure products allow Denial of Service via the aepack archive unpack handler. This affects WithSecure Client Security 15, WithSEPSS 0.6%CVE-2026-63016MEDIUMApache InLong: Ordinary users can create new packagesEPSS 0.6%CVE-2022-41568HIGHLINE client for iOS before 12.17.0 might be crashed by sharing an invalid shared key of e2ee in group chat.EPSS 0.6%CVE-2026-40481HIGHmonetr: Unauthenticated Stripe webhook reads attacker-sized request bodies before signature validationEPSS 0.6%CVE-2023-21925MEDIUMVulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (component: Core). Supported versions thaEPSS 0.6%CVE-2023-48369MEDIUMLog Flooding due to specially crafted requests in different endpointsEPSS 0.6%CVE-2025-7074MEDIUMvercel hyper rimraf-standalone.js ignoreMap redosEPSS 0.6%CVE-2025-25186MEDIUMNet::IMAP vulnerable to possible DoS by memory exhaustionEPSS 0.6%CVE-2026-85443HIGHMOOS core-moos through 10.4.0 MOOSDB Accept Loop Denial of ServiceEPSS 0.6%