Fallos del tipo CWE-400

3033 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2026-52192HIGHAn issue in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_445C5C componenEPSS 0.6%CVE-2026-76646HIGHApache MyFaces: Denial of Service via Unbounded Request ParsingEPSS 0.6%CVE-2026-67862HIGHopen62541 1.5.5 contains a buffer-overflow in the high-level attribute reading logic in src/client/ua_client_highlevel.c. This allows a remoEPSS 0.6%CVE-2023-29139MEDIUMAn issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. When a user with checkuserlog permissions makes many CheckUEPSS 0.6%CVE-2026-26047MEDIUMMoodle: moodle: uncontrolled resource consumption in tex formula editor leading to denial of serviceEPSS 0.6%CVE-2026-68005HIGHAn issue in ACME mini_httpd 1.30 and prior allows a remote attacker to cause a denial of service via the HTTP request header parser in the hEPSS 0.6%CVE-2026-77037HIGHmulter vulnerable to Denial of Service via file descriptor leak on aborted uploadsEPSS 0.6%CVE-2026-52197HIGHAn issue in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_44af70 componenEPSS 0.6%CVE-2023-45196MEDIUMAdminer and AdminerEvo denial of service via HTTP redirectEPSS 0.6%CVE-2026-55446HIGHLangflow: Unauthenticated DoS through multipart form boundary file uploadEPSS 0.6%CVE-2026-68497HIGHjackson-databind: unbounded numeric parse in Duration and XMLGregorianCalendar deserialization allows CPU denial of serviceEPSS 0.6%CVE-2023-20882MEDIUMIn Cloud foundry routing release versions from 0.262.0 and prior to 0.266.0,a bug in the gorouter process can lead to a denial of service ofEPSS 0.6%CVE-2026-34043MEDIUMSerialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objectsEPSS 0.6%CVE-2024-34079LOWocto-sts allows unauthenticated attackers to cause unbounded CPU and memory usageEPSS 0.6%CVE-2026-81721HIGHopenssl_encrypt before 1.4.9 Denial of Service via KDFEPSS 0.6%CVE-2026-49842HIGHFreeSWITCH: Pre-authentication bandwidth amplification via `mod_verto` speed-test framesEPSS 0.6%CVE-2026-65785MEDIUMWindows DHCP Client Denial of Service VulnerabilityEPSS 0.6%CVE-2025-53042MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.EPSS 0.6%CVE-2025-53040MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.EPSS 0.6%CVE-2025-53044MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.43, 8.4.0EPSS 0.6%