Fallos del tipo CWE-400

3033 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2024-5795HIGHDenial of Service vulnerability was identified in GitHub Enterprise Server that allowed resource exhaustionEPSS 0.6%CVE-2023-29333LOWMicrosoft Access Denial of Service VulnerabilityEPSS 0.6%CVE-2026-73228MEDIUMDjango REST framework: Potential bypass of Django `DATA_UPLOAD_MAX_MEMORY_SIZE` when parsing oversized JSON and urlencoded request bodies via DRF `request.data`EPSS 0.6%CVE-2023-24594MEDIUMBIG-IP TMM SSL vulnerabilityEPSS 0.6%CVE-2023-51847HIGHAn issue in obgm and Libcoap v.a3ed466 allows a remote attacker to cause a denial of service via thecoap_context_t function in the src/coap_EPSS 0.6%CVE-2024-44169HIGHThe issue was addressed with improved memory handling. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia EPSS 0.6%CVE-2026-9322HIGHIBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilitiesEPSS 0.6%CVE-2024-27100MEDIUMDenial of service via Staff Actions in DiscourseEPSS 0.6%CVE-2023-7326HIGHEpson Stylus SX510W Printer Remote Power Off DoSEPSS 0.6%CVE-2025-62854LOWFile Station 5EPSS 0.6%CVE-2023-39327MEDIUMOpenjpeg: malicious files can cause the program to enter a large loopEPSS 0.6%CVE-2021-47208MEDIUMThe Mojolicious module before 9.11 for Perl has a bug in format detection that can potentially be exploited for denial of service.EPSS 0.6%CVE-2026-22258HIGHSuricata DCERPC: unbounded fragment buffering leads to memory exhaustionEPSS 0.6%CVE-2024-42969HIGHTenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromSafeUrlFilter function. This vulnerabEPSS 0.6%CVE-2024-42950HIGHTenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the Go parameter in the fromSafeClientFilter function. This vulnEPSS 0.6%CVE-2024-20500MEDIUMA vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unEPSS 0.6%CVE-2024-42951HIGHTenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the mit_pptpusrpw parameter in the fromWizardHandle function. ThEPSS 0.6%CVE-2022-41932HIGHCreation of new database tables through login form on PostgreSQLEPSS 0.6%CVE-2026-26477MEDIUMAn issue in Dokuwiki v.2025-05-14b "Librarian" [56.2] allows a remote attacker to cause a denial of service via the media_upload_xhr() functEPSS 0.6%CVE-2024-27862MEDIUMA logic issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.6. Enabling Lockdown Mode while setting uEPSS 0.6%