Fallos del tipo CWE-400

3033 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2024-55568HIGHAn issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380,EPSS 0.6%CVE-2026-33285HIGHLiquidJS: memoryLimit Bypass through Negative Range Values Leads to Process CrashEPSS 0.6%CVE-2025-26782HIGHAn issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330,EPSS 0.6%CVE-2026-86515MEDIUMvgmstream txtp txtp_parser.c add_entry resource consumptionEPSS 0.6%CVE-2025-21547CRITICALVulnerability in the Oracle Hospitality OPERA 5 product of Oracle Hospitality Applications (component: Opera Servlet). Supported versions tEPSS 0.6%CVE-2026-92879MEDIUMvgmstream mus_acm.c parse_mus resource consumptionEPSS 0.6%CVE-2024-24827MEDIUMNo rate limits on POST /uploads endpoint in DiscourseEPSS 0.6%CVE-2024-25355HIGHs3-url-parser 1.0.3 is vulnerable to Denial of service via the regexes component.EPSS 0.6%CVE-2023-45955—An issue discovered in Nanoleaf Light strip v3.5.10 allows attackers to cause a denial of service via crafted write binding attribute commanEPSS 0.6%CVE-2023-26437LOWDeterred spoofing attempts can lead to authoritative servers being marked unavailableEPSS 0.6%CVE-2024-34084HIGHMinder's Github Webhook Handler vulnerable to denial of service from un-validated requestsEPSS 0.6%CVE-2025-50077MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.42, 8.4.0EPSS 0.6%CVE-2025-50089MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 9.0.0-9.EPSS 0.6%CVE-2025-50079MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.EPSS 0.6%CVE-2026-33268MEDIUMNanoleaf Lines unauthenticated firmware file storeEPSS 0.6%CVE-2025-50091MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.EPSS 0.6%CVE-2025-55796HIGHThe openml/openml.org web application version v2.0.20241110 uses predictable MD5-based tokens for critical user workflows such as signup conEPSS 0.6%CVE-2025-0191MEDIUMDenial of Service in gaizhenbiao/chuanhuchatgptEPSS 0.6%CVE-2024-27686HIGHMikrotik RouterOS (x86) 6.40.5 through 6.49.10 (fixed in 7) allows a remote attacker to cause a denial of service (device crash) via craftedEPSS 0.6%CVE-2026-44630HIGHApache IoTDB: RPC service denial of service via unchecked Thrift string lengthEPSS 0.6%