Fallos del tipo CWE-400

3026 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2026-45756HIGHSymfony: JsonPath Evaluates Attacker-Controlled Regular Expressions in match()/search() Without Limits — ReDoSEPSS 0.6%CVE-2026-81875HIGHHAPI FHIR: SHCParser unbounded DEFLATE decompression causes denial of serviceEPSS 0.6%CVE-2026-45169HIGHIdira Privileged Access Manager (PAM) Self-Hosted Vault: Denial of Service due to Unexpected Input ProcessingEPSS 0.6%CVE-2026-47736HIGHPuma PROXY Protocol v1 Parser Allows Remote Memory ExhaustionEPSS 0.6%CVE-2026-55099HIGHicalendar: Algorithmic Complexity in EqualityEPSS 0.6%CVE-2026-81876HIGHHAPI FHIR: SHCParser DEFLATE infinite loop causes denial of serviceEPSS 0.6%CVE-2026-69222HIGHLiquidJS: Uncontrolled Resource Consumption in `join` filter allows template authors to bypass `memoryLimit` and crash the processEPSS 0.6%CVE-2026-85443HIGHMOOS core-moos through 10.4.0 MOOSDB Accept Loop Denial of ServiceEPSS 0.6%CVE-2026-9496HIGHVersions of the package pacote from 11.2.7 and before 21.5.1 are vulnerable to Denial of Service (DoS) via the addGitSha function. An attackEPSS 0.6%CVE-2026-45664MEDIUMImageMagick: Policy Bypass in MNG coder couldEPSS 0.6%CVE-2026-49851HIGHMistune: Potential DoS via quadratic-time parsing in parse_link_textEPSS 0.6%CVE-2026-69213HIGHHttp4s Ember HTTP/2: unbounded outbound frame queueEPSS 0.6%CVE-2026-38640HIGHA reachable unwrap in the __assert_fail function (/assert/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Service (DoSEPSS 0.6%CVE-2026-63452HIGHSuricata http1: repeated brotli compression bombs can cause excessive CPU consumptionEPSS 0.6%CVE-2026-55851HIGHNetty codec-haproxy: Signed-Byte Sentinel Collision in HAProxyMessageDecoder Leads to Unbounded Memory ExhaustionEPSS 0.6%CVE-2026-56745HIGHNetty SpdyHttpDecoder: ByteBuf Reference Leak on RST_STREAM Leads to Native Memory ExhaustionEPSS 0.6%CVE-2026-38637HIGHAn issue in the pthread_rwlockattr_setpshared() function of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a cEPSS 0.6%CVE-2026-38638HIGHAn issue in the with_argv function (/unistd/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafteEPSS 0.6%CVE-2026-69202HIGHHttp4s Ember HTTP/2: unbounded inbound body bufferingEPSS 0.6%CVE-2026-9563HIGHIn Eclipse Parsson published Maven Central artifacts before version 1.1.8, the JSON parser did not enforce a default maximum on the number oEPSS 0.6%