Fallos del tipo CWE-400

3030 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2026-21452HIGHMessagePack-Java Vulnerable to Remote Denial of Service via Malicious .msgpack Model File Triggering Unbounded EXT Payload AllocationEPSS 0.6%CVE-2023-20259HIGHA vulnerability in an API endpoint of multiple Cisco Unified Communications Products could allow an unauthenticated, remote attacker to causEPSS 0.6%CVE-2026-71310MEDIUMrclone: Unbounded HTTP CONNECT Response Headers Can Exhaust rclone MemoryEPSS 0.6%CVE-2024-4183MEDIUMMattermost versions 8.1.x before 8.1.12, 9.6.x before 9.6.1, 9.5.x before 9.5.3, 9.4.x before 9.4.5 fail to limit the number of active sessiEPSS 0.6%CVE-2025-20340HIGHCisco IOS XR Address Resolution Protocol Broadcast Storm VulnerabilityEPSS 0.6%CVE-2026-71643HIGHAn issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denEPSS 0.6%CVE-2026-68523HIGHFulgur: Unbounded page slicing from attacker-controlled CSS height causes denial of serviceEPSS 0.6%CVE-2026-53504HIGHThumbor has Regex Denial of Service (ReDoS) in `convolution` filterEPSS 0.6%CVE-2026-63495HIGHLibevent: Unbounded memory accumulation in WebSocket server via fragmented framesEPSS 0.6%CVE-2026-86000MEDIUMSoup Sieve: Polynomial-time ReDoS (O(n²)) in the `IDENTIFIER` / `VALUE` selector sub-patternsEPSS 0.6%CVE-2026-68537HIGHFulgur: Unbounded page slicing from attacker-controlled CSS height causes denial of serviceEPSS 0.6%CVE-2026-71647HIGHAn issue in EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denial of servicEPSS 0.6%CVE-2026-71641HIGHAn issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denEPSS 0.6%CVE-2026-73561HIGHHub: Unauthenticated WebSocket RPC Waiter Resource ExhaustionEPSS 0.6%CVE-2026-79378HIGHAn issue in the btm_acl_handle() function of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware v3.x and earlier allows attackers to cEPSS 0.6%CVE-2026-85999MEDIUMSoup Sieve: Polynomial-time ReDoS (O(n²)) in the whitespace/comment trimming regex `RE_WS_END` (triggers on VALID selectors)EPSS 0.6%CVE-2026-56018HIGHJavaScript::Minifier::XS versions before 0.16 for Perl leak memory on every call to minify(), allowing unbounded memory growthEPSS 0.6%CVE-2026-53505HIGHThumbor proportion filter allows unbounded post-transform resize leading to remote DoSEPSS 0.6%CVE-2026-84304HIGHgRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame FragmentationEPSS 0.6%CVE-2026-50196HIGHSteeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetchEPSS 0.6%