Fallos del tipo CWE-400

3027 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2026-45765HIGHSuricata dnp3: unbounded reassembly can lead to resource exhaustionEPSS 0.6%CVE-2023-23689MEDIUM Dell PowerScale nodes A200, A2000, H400, H500, H600, H5600, F800, F810 integrated hardware management software contains an uncontrolled resEPSS 0.6%CVE-2023-22400HIGHJunos OS Evolved: A specific SNMP GET operation and a specific CLI commands cause resources to leak and eventually the evo-pfemand process will crashEPSS 0.6%CVE-2026-45766HIGHSuricata nfs: unbounded stateful structures can lead to resource exhaustionEPSS 0.6%CVE-2026-59886HIGHpyasn1: Uncontrolled resource consumption when converting decoded REAL valuesEPSS 0.6%CVE-2023-1580HIGHUncontrolled resource consumption in the logging feature in Devolutions Gateway 2023.1.1 and earlier allows an attacker to cause a denial ofEPSS 0.6%CVE-2026-67318MEDIUMaxios 1.13.0 before 1.18.0 maxBodyLength Bypass via HTTP/2EPSS 0.6%CVE-2025-32472MEDIUMDoS attack by conducting a slowloris-type attackEPSS 0.6%CVE-2026-50193MEDIUMjackson-databind: Deeply nested JsonNode throws StackOverflowError for toString()EPSS 0.6%CVE-2023-35053HIGHIn JetBrains YouTrack before 2023.1.10518 a DoS attack was possible via Helpdesk formsEPSS 0.6%CVE-2025-5895MEDIUMMetabase dom.js parseDataUri redosEPSS 0.6%CVE-2026-53965MEDIUMMCP PHP SDK: Unbounded SSE buffer in HttpTransport enables client-side denial of serviceEPSS 0.6%CVE-2024-30170HIGHPrivX before 34.0 allows data exfiltration and denial of service via the REST API. This is fixed in minor versions 33.1, 32.3, 31.3, and latEPSS 0.6%CVE-2026-32936HIGHCoreDNS DoH GET path missing size validation causes CPU and memory amplificationEPSS 0.6%CVE-2026-33750MEDIUMbrace-expansion: Zero-step sequence causes process hang and memory exhaustionEPSS 0.6%CVE-2023-28763MEDIUMDenial of Service in SAP NetWeaver AS for ABAP and ABAP PlatformEPSS 0.6%CVE-2023-27270MEDIUMDenial of Service (DoS) in SAP NetWeaver AS for ABAP and ABAP PlatformEPSS 0.6%CVE-2024-8454MEDIUMPLANET Technology switch devices - Swctrl service DoS attackEPSS 0.6%CVE-2026-100650HIGHvLLM before 0.29.0 Resource Exhaustion via Unbounded Media MaterializationEPSS 0.6%CVE-2023-25618MEDIUMDenial of Service (DoS) vulnerability in SAP NetWeaver AS for ABAP and ABAP PlatformEPSS 0.6%