Fallos del tipo CWE-400

3034 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2024-42981HIGHTenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the delno parameter in the fromPptpUserSetting function. This vulneEPSS 0.6%CVE-2026-26477MEDIUMAn issue in Dokuwiki v.2025-05-14b "Librarian" [56.2] allows a remote attacker to cause a denial of service via the media_upload_xhr() functEPSS 0.6%CVE-2026-85703MEDIUMramon-victor freegpt-webui Jailbreak Mode backend.py getJailbreak allocation of resourcesEPSS 0.6%CVE-2025-41676MEDIUMResource Exhaustion via POST Requests to send-sms ActionEPSS 0.6%CVE-2024-8451HIGHPLANET Technology switch devices - SSH server DoS attackEPSS 0.6%CVE-2023-42358HIGHAn issue was discovered in O-RAN Software Community ric-plt-e2mgr in the G-Release environment, allows remote attackers to cause a denial ofEPSS 0.6%CVE-2026-16818HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.5%CVE-2026-16831HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.5%CVE-2026-9171HIGHVulnerabilities in IBM WebSphere Application affects IBM PowerVM Novalink.EPSS 0.5%CVE-2026-17121HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.5%CVE-2026-16824HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.5%CVE-2026-23842HIGHChatterBot has Denial of Service via Database Connection Pool ExhaustionEPSS 0.5%CVE-2026-36478HIGHAn issue in Technitium DNS Server v.14.3 and before allows a remote attacker to cause a denial of service via the DnsServerApp.exe, DnsServeEPSS 0.5%CVE-2026-16836HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.5%CVE-2026-16690HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.5%CVE-2023-1206—A hash collision flaw was found in the IPv6 connection lookup table in the Linux kernel’s IPv6 functionality when a user makes a new kind ofEPSS 0.5%CVE-2025-31118HIGHNamelessMC Has Forum Reply Submission Time Limit BypassEPSS 0.5%CVE-2026-86734HIGHSnipe-IT before 8.7.1 Denial of Service via Unbounded Note FieldEPSS 0.5%CVE-2026-73559MEDIUMvLLM: Completion prompt lists fan out into unbounded engine requestsEPSS 0.5%CVE-2025-30158HIGHNamelessMC Forum iframe width/height abuse causing UI-based Denial of ServiceEPSS 0.5%