Fallos del tipo CWE-400

3030 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2026-42493HIGHx86 shadow paging is deprecatedEPSS 0.6%CVE-2026-68523HIGHFulgur: Unbounded page slicing from attacker-controlled CSS height causes denial of serviceEPSS 0.6%CVE-2026-50196HIGHSteeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetchEPSS 0.6%CVE-2023-3593MEDIUMServer crash via a specially crafted markdown inputEPSS 0.6%CVE-2026-94640HIGHRpcbind: unbounded memory allocation in rpcbind statistics tracking allows unauthenticated remote denial of serviceEPSS 0.6%CVE-2024-22332MEDIUMIBM Integration Bus for z/OS denial of serviceEPSS 0.6%CVE-2026-45713HIGHMailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizesEPSS 0.6%CVE-2025-5896MEDIUMtarojs taro index.js redosEPSS 0.6%CVE-2023-32341MEDIUMIBM Sterling B2B Integrator denial of serviceEPSS 0.6%CVE-2026-0889HIGHDenial-of-service in the DOM: Service Workers componentEPSS 0.6%CVE-2024-27800HIGHThis issue was addressed by removing the vulnerable code. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macEPSS 0.6%CVE-2026-18549HIGH@fastify/multipart vulnerable to Denial of Service via aborted upload after fileSize limitEPSS 0.6%CVE-2025-5892MEDIUMRocketChat parseMessage.js parseMessage redosEPSS 0.6%CVE-2024-11498MEDIUMResource exhaustion via Stack overflow in libjxlEPSS 0.6%CVE-2022-37907MEDIUMA vulnerability exists in the ArubaOS bootloader on 7xxx series controllers which can result in a denial of service (DoS) condition on an imEPSS 0.6%CVE-2025-5897MEDIUMvuejs vue-cli Markdown Code HtmlPwaPlugin.js HtmlPwaPlugin redosEPSS 0.6%CVE-2024-21523HIGHAll versions of the package images are vulnerable to Denial of Service (DoS) due to providing unexpected input types to several different fuEPSS 0.6%CVE-2023-42503—Apache Commons Compress: Denial of service via CPU consumption for malformed TAR fileEPSS 0.6%CVE-2024-27354HIGHAn issue was discovered in phpseclib 1.x before 1.0.23, 2.x before 2.0.47, and 3.x before 3.0.36. An attacker can construct a malformed certEPSS 0.6%CVE-2023-2785MEDIUMSpecially crafted search query can cause large log entries in postgresEPSS 0.6%