Fallos del tipo CWE-400

3030 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2023-23524HIGHA denial-of-service issue was addressed with improved input validation. This issue is fixed in tvOS 16.3.2, iOS 16.3.1 and iPadOS 16.3.1, waEPSS 0.6%CVE-2025-8537MEDIUMAxiomatic Bento4 mp4decrypt Mp4Decrypt.cpp SetDataSize allocation of resourcesEPSS 0.6%CVE-2024-47497HIGHJunos OS: SRX Series, QFX Series, MX Series and EX Series: Receiving specific HTTPS traffic causes resource exhaustionEPSS 0.6%CVE-2025-65891HIGHA GPU device-ID validation flaw in OneFlow v0.9.0 allows attackers to trigger a Denial of Dervice (DoS) by invoking flow.cuda.get_device_proEPSS 0.6%CVE-2024-37299MEDIUMDiscourse vulnerable to DoS via Tag GroupEPSS 0.6%CVE-2021-23047—On version 16.x before 16.1.0, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.3, and all versions of 13.1.x, 12.1.x and 11.6.x, when BIG-IP APEPSS 0.6%CVE-2025-48392HIGHApache IoTDB: DoS VulnerabilityEPSS 0.6%CVE-2024-21521HIGHAll versions of the package @discordjs/opus are vulnerable to Denial of Service (DoS) due to providing an input object with a property toStrEPSS 0.6%CVE-2026-55512MEDIUMnebula-mesh: Unauthenticated OIDC login endpoint allocates unbounded in-memory state entries without rate limitingEPSS 0.6%CVE-2025-9281HIGHArmorStart® LT - Multiple Denial-of-Service VulnerabilitiesEPSS 0.6%CVE-2025-9279HIGHArmorStart® LT - Multiple Denial-of-Service VulnerabilitiesEPSS 0.6%CVE-2025-9283HIGHArmorStart® LT - Multiple Denial-of-Service VulnerabilitiesEPSS 0.6%CVE-2025-9282HIGHArmorStart® LT - Multiple Denial-of-Service VulnerabilitiesEPSS 0.6%CVE-2025-43462HIGHThe issue was addressed with improved memory handling. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOEPSS 0.6%CVE-2024-23824MEDIUMmailcow ipixel flood attack leads to Denial of Service in admin pageEPSS 0.6%CVE-2026-21619LOWUnsafe Deserialization of Erlang Terms in hex_coreEPSS 0.6%CVE-2026-30041HIGHAn integer overflow in the PSD parser compnent of FastStone Image Viewer v8.3 allows attackers to execute arbitrary code or cause a Denial oEPSS 0.6%CVE-2026-74789HIGHScriban before 7.0.0 LoopLimit Bypass via Built-in OperationsEPSS 0.6%CVE-2022-46315HIGHThe ProfileSDK has defects introduced in the design process. Successful exploitation of this vulnerability may affect system availability. EPSS 0.6%CVE-2026-33285HIGHLiquidJS: memoryLimit Bypass through Negative Range Values Leads to Process CrashEPSS 0.6%