Fallos del tipo CWE-400

3034 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2023-26157MEDIUMVersions of the package libredwg before 0.12.5.6384 are vulnerable to Denial of Service (DoS) due to an out-of-bounds read involving sectionEPSS 0.5%CVE-2026-21696HIGHEndless reprocessing/reupload of activity log data due to SQLite max parameters limit not being consideredEPSS 0.5%CVE-2022-24902LOWMemory issue in playing videosEPSS 0.5%CVE-2025-44650HIGHIn Netgear R7000 V1.3.1.64_10.1.36 and EAX80 V1.0.1.70_1.0.2, the USERLIMIT_GLOBAL option is set to 0 in the bftpd.conf configuration file. EPSS 0.5%CVE-2026-33204HIGHSimpleJWT has an Unauthenticated Denial of Service via JWE header tamperingEPSS 0.5%CVE-2023-34061HIGHCVE-2023-34061 – Gorouter route pruningEPSS 0.5%CVE-2023-3585MEDIUMchannel DoS by sharing a boards linkEPSS 0.5%CVE-2026-41135HIGHfree5GC PCF: Memory Leak via CORS Middleware Registration in HTTP Handler Leads to Denial of ServiceEPSS 0.5%CVE-2025-52322HIGHAn issue in Open5GS v2.7.2 and before allows a remote attacker to cause a denial of service via a crafted Create Session Request message to EPSS 0.5%CVE-2026-55588MEDIUMORAS CLI: Cyclic Referrer Graph Can Cause Unbounded Recursion and Resource ConsumptionEPSS 0.5%CVE-2025-50076MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.0-8.0.25. EPSS 0.5%CVE-2024-52980MEDIUMElasticsearch Uncontrolled Resource Consumption vulnerabilityEPSS 0.5%CVE-2024-22091LOWExcessive resource consumption due to lack to request path size limitsEPSS 0.5%CVE-2024-45736MEDIUMImproperly Formatted ‘INGEST_EVAL’ Parameter Crashes Splunk DaemonEPSS 0.5%CVE-2026-47476HIGHNVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource consumption. A successfuEPSS 0.5%CVE-2024-54658MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOSEPSS 0.5%CVE-2024-27088NONEes5-ext Regular Expression Denial of Service in `function#copy` and `function#toStringTokens`EPSS 0.5%CVE-2025-2586HIGHOls: unauthenticated metrics flooding in openshift lightspeed service leading to resource exhaustionEPSS 0.5%CVE-2025-67726HIGHTornado is Vulnerable to Quadratic DoS via Crafted Multipart ParametersEPSS 0.5%CVE-2026-28351MEDIUMManipulated RunLengthDecode streams can exhaust RAMEPSS 0.5%