Fallos del tipo CWE-400

3033 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2024-27085MEDIUMDenial of service through invites in DiscourseEPSS 0.6%CVE-2022-4344MEDIUMMemory exhaustion in the Kafka protocol dissector in Wireshark 4.0.0 to 4.0.1 and 3.6.0 to 3.6.9 allows denial of service via packet injectiEPSS 0.6%CVE-2026-78684MEDIUMvLLM before 0.27.0 Denial of Service via DeepStream BackendEPSS 0.6%CVE-2026-54886MEDIUMSSH SFTP server denial of service via extended channel data infinite loopEPSS 0.6%CVE-2026-33818HIGHEnforce maximum recursion depth in encoding/asn1EPSS 0.6%CVE-2026-28908HIGHA denial of service issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, mEPSS 0.6%CVE-2026-61814HIGHJawn: Quadratic parsing effort in AsyncParserEPSS 0.6%CVE-2026-34166LOWLiquidJS has a Memory Limit Bypass via Quadratic Amplification in `replace` FilterEPSS 0.6%CVE-2025-30160HIGHRedlib allows a Denial of Service via DEFLATE Decompression Bomb in restore_preferences FormEPSS 0.6%CVE-2025-69534HIGHPython-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandlEPSS 0.6%CVE-2020-3505MEDIUMCisco Video Surveillance 8000 Series IP Cameras Cisco Discovery Protocol Memory Leak VulnerabilityEPSS 0.6%CVE-2024-21655MEDIUMInsufficient control of custom field value sizesEPSS 0.6%CVE-2025-24294HIGHThe attack vector is a potential Denial of Service (DoS). The vulnerability is caused by an insufficient check on the length of a decompressEPSS 0.6%CVE-2026-9320MEDIUMIBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilitiesEPSS 0.6%CVE-2025-50082MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.EPSS 0.6%CVE-2025-68272HIGHSignal K Server Vulnerable to Denial of Service via Unrestricted Access Request FloodingEPSS 0.6%CVE-2025-50088MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0EPSS 0.6%CVE-2025-50078MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.0-8.0.42, EPSS 0.6%CVE-2023-22396HIGHJunos OS: Receipt of crafted TCP packets destined to the device results in MBUF leak leading to a Denial of Service (DoS)EPSS 0.6%CVE-2025-35432MEDIUMCISA Thorium does not rate limit account verification email messagesEPSS 0.6%