Fallos del tipo CWE-400

3033 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2026-76686HIGHUnauthenticated Denial-of-Service (DoS) Vulnerability leads to Service Disruption in HPE Networking EdgeConnect SD-WAN GatewaysEPSS 0.6%CVE-2026-73786HIGHUnauthenticated Network-Based Denial of Service in CPPM systemsEPSS 0.6%CVE-2024-57075HIGHA prototype pollution in the lib.Logger function of eazy-logger v4.0.1 allows attackers to cause a Denial of Service (DoS) via supplying a cEPSS 0.6%CVE-2026-45047HIGHbird-lg-go: Fatal Out-of-Memory (OOM) Denial of Service via Unbounded JSON DecodingEPSS 0.6%CVE-2026-48937MEDIUMA flaw in Node.js HTTP/2 server API can cause servers to keep accepting data even after sending a `GOAWAY` frame. This vulnerability affectsEPSS 0.6%CVE-2024-52981MEDIUMAn issue was discovered in Elasticsearch, where a large recursion using the Well-KnownText formatted string with nested GeometryCollection oEPSS 0.6%CVE-2023-29185MEDIUMDenial of Service (DOS) in SAP NetWeaver AS for ABAP (Business Server Pages)EPSS 0.6%CVE-2026-28221MEDIUMWazuh: Pre-auth stack-based buffer overflow in wazuh-remoted print_hex_string() due to signed char promotion on x86_64EPSS 0.6%CVE-2022-36326MEDIUMResource Exhaustion Vulnerability in Western Digital devicesEPSS 0.6%CVE-2025-5889LOWjuliangruber brace-expansion index.js expand redosEPSS 0.6%CVE-2026-92003MEDIUMMISP Unthrottled Authentication Failure Log Writes Enable Resource ExhaustionEPSS 0.6%CVE-2025-44203HIGHIn HotelDruid 3.0.0 and 3.0.7, the unauthenticated database-setup endpoint creadb.php can be reached before setup is completed and performs EPSS 0.6%CVE-2025-30752LOWVulnerability in the Oracle Java SE, Oracle GraalVM for JDK product of Oracle Java SE (component: Compiler). The supported version that isEPSS 0.6%CVE-2026-73216MEDIUMcoturn: mobility disconnects bypass allocation quotas and exhaust relay capacityEPSS 0.6%CVE-2024-6427HIGHUncontrolled Resource Consumption vulnerability in MESbookEPSS 0.6%CVE-2024-28122MEDIUM JWX vulnerable to a denial of service attack using compressed JWE messageEPSS 0.6%CVE-2024-21526HIGHAll versions of the package speaker are vulnerable to Denial of Service (DoS) when providing unexpected input types to the channels propertyEPSS 0.6%CVE-2026-44645MEDIUMLiquidJS has a renderLimit DoS guard bypass via empty `{% for %}` bodyEPSS 0.6%CVE-2024-27085MEDIUMDenial of service through invites in DiscourseEPSS 0.6%CVE-2026-78684MEDIUMvLLM before 0.27.0 Denial of Service via DeepStream BackendEPSS 0.6%