Fallos del tipo CWE-400

3026 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2023-28644MEDIUMReference fetch can saturate the server bandwidth for 10 seconds in nextcloud serverEPSS 0.6%CVE-2024-10912HIGHDenial of Service in lm-sys/fastchatEPSS 0.6%CVE-2025-3016MEDIUMOpen Asset Import Library Assimp MDL File MDLMaterialLoader.cpp ParseTextureColorData resource consumptionEPSS 0.6%CVE-2026-9071HIGHIBM WebSphere Application Server and WebSphere Application Server Liberty are affected by Uncontrolled Resource ConsumptionEPSS 0.6%CVE-2025-3985MEDIUMApereo CAS ResponseEntity redosEPSS 0.6%CVE-2023-37900LOWCrossplane vulnerable to denial of service from large imageEPSS 0.6%CVE-2025-65518HIGHPlesk Obsidian versions 8.0.1 through 18.0.73 are vulnerable to a Denial of Service (DoS) condition. The vulnerability exists in the get_pasEPSS 0.6%CVE-2024-23814MEDIUMThe integrated ICMP service of the network stack of affected devices can be forced to exhaust its available memory resources when receivingEPSS 0.6%CVE-2024-26369HIGHAn issue in the HistoryQosPolicy component of FastDDS v2.12.x, v2.11.x, v2.10.x, and v2.6.x leads to a SIGABRT (signal abort) upon receivingEPSS 0.6%CVE-2026-61387MEDIUMIn Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting is not exception-safe: if item creation fails with an uncheckeEPSS 0.6%CVE-2026-59936HIGHpypdf: Possible infinite loop for not terminated inline imagesEPSS 0.6%CVE-2026-59937MEDIUMpypdf: Possible long runtimes for repeated malformed cross-reference entriesEPSS 0.6%CVE-2026-20652HIGHThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOSEPSS 0.6%CVE-2023-6180MEDIUMResource exhaustion via memory leak in tokio-boringEPSS 0.6%CVE-2026-55241HIGHCheckmate: Pre-auth Denial of Service via File Upload on RegistrationEPSS 0.6%CVE-2025-3112HIGHCWE-400: Uncontrolled Resource Consumption vulnerability exists that could cause Denial of Service when an authenticated malicious user sendEPSS 0.6%CVE-2022-38734—StorageGRID (formerly StorageGRID Webscale) versions prior to 11.6.0.8 are susceptible to a Denial of Service (DoS) vulnerability. A successEPSS 0.6%CVE-2024-56200HIGHUncontrolled Recursion and Asymmetric Resource Consumption in Altair media/file proxyEPSS 0.6%CVE-2026-59885HIGHpyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of serviceEPSS 0.6%CVE-2025-32472MEDIUMDoS attack by conducting a slowloris-type attackEPSS 0.6%