Fallos del tipo CWE-400

3033 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2023-22396HIGHJunos OS: Receipt of crafted TCP packets destined to the device results in MBUF leak leading to a Denial of Service (DoS)EPSS 0.6%CVE-2025-61600HIGHUnbounded Memory Allocation in Stalwart IMAP parserEPSS 0.6%CVE-2025-35432MEDIUMCISA Thorium does not rate limit account verification email messagesEPSS 0.6%CVE-2023-5196MEDIUMDoS via Channel Notification PropertiesEPSS 0.6%CVE-2024-28949MEDIUMDoS via a large number of User PreferencesEPSS 0.6%CVE-2023-2793MEDIUMStack exhaustion in PreparePostForClientWithEmbedsAndImagesEPSS 0.6%CVE-2022-48475HIGHBuffer Overflow vulnerability in Control de Ciber version 1.650, in the printing function. Sending a modified request by the attacker could EPSS 0.6%CVE-2025-61771HIGHRack's multipart parser buffers large non‑file fields entirely in memory, enabling DoS (memory exhaustion)EPSS 0.6%CVE-2018-25100MEDIUMThe Mojolicious module before 7.66 for Perl may leak cookies in certain situations related to multiple similar cookies for the same domain. EPSS 0.6%CVE-2026-53954MEDIUMBugsink: DOS using large numbers of event tagsEPSS 0.6%CVE-2024-43647HIGHA vulnerability has been identified in SIMATIC S7-200 SMART CPU CR40 (6ES7288-1CR40-0AA0) (All versions), SIMATIC S7-200 SMART CPU CR60 (6ESEPSS 0.6%CVE-2026-44796MEDIUMNautobot: Object bulk rename UI actions vulnerable to denial of service by crafted regular expression (REDoS)EPSS 0.6%CVE-2024-4284MEDIUMDenial of Service in mintplex-labs/anything-llmEPSS 0.6%CVE-2025-48956HIGHvLLM API endpoints vulnerable to Denial of Service AttacksEPSS 0.6%CVE-2025-50092MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.42, 8.4.0EPSS 0.6%CVE-2025-67725HIGHTornado is Vulnerable to Quadratic DoS via Repeated Header CoalescingEPSS 0.6%CVE-2026-63015MEDIUMApache InLong: Non-template responsible persons can view template informationEPSS 0.6%CVE-2025-50093MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.0-8.0.42, EPSS 0.6%CVE-2025-20370MEDIUMDenial of Service (DoS) through Multiple LDAP Bind Requests in Splunk EnterpriseEPSS 0.6%CVE-2024-10188HIGHDenial of Service in BerriAI/litellmEPSS 0.6%