Fallos del tipo CWE-400

3034 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2025-6493MEDIUMCodeMirror Markdown Mode markdown.js redosEPSS 0.5%CVE-2026-8968HIGHDenial-of-service due to invalid pointer in the Audio/Video: Web Codecs componentEPSS 0.5%CVE-2026-37234HIGHFlexRIC v2.0.0 allows a single SCTP connection to bind multiple xapp_ids by sending multiple E42_SETUP_REQUESTs. On disconnect, only the firEPSS 0.5%CVE-2026-74982HIGHDenial-of-service in the Widget componentEPSS 0.5%CVE-2026-92361MEDIUMag-ui-protocol ag-ui SSE Client client.go resource consumptionEPSS 0.5%CVE-2026-85718MEDIUMAsyncHttpClient: Connection permit leak on TLS handshake failure causes per-host denial of serviceEPSS 0.5%CVE-2024-4557MEDIUMUncontrolled Resource Consumption in GitLabEPSS 0.5%CVE-2026-93307MEDIUMO-RAN-SC SMO OAM VES Collector memory allocationEPSS 0.5%CVE-2026-90878MEDIUMvllm-project vLLM Jinja Template Rendering completions resource consumptionEPSS 0.5%CVE-2020-9060—Z-Wave devices based on Silicon Labs 500 series chipsets using S2, including but likely not limited to the ZooZ ZST10 version 6.04, ZooZ ZENEPSS 0.5%CVE-2026-88932MEDIUMmulter vulnerable to Denial of Service via orphaned disk writes on aborted uploadsEPSS 0.5%CVE-2026-33235HIGHAutoGPT: Denial of Service (DoS) via Resource Exhaustion in text templating featuresEPSS 0.5%CVE-2025-56572HIGHAn issue in finance.js v.4.1.0 allows a remote attacker to cause a denial of service via the seekZero() parameter.EPSS 0.5%CVE-2026-12523HIGHResource exhaustion in quiche HTTP/3 and QPACK layersEPSS 0.5%CVE-2023-44388HIGHMalicious requests can fill up the log files resulting in a deinal of service in DiscourseEPSS 0.5%CVE-2025-31210MEDIUMThe issue was addressed with improved UI. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7. Processing web content may lead toEPSS 0.5%CVE-2025-32392HIGHAutoGPT has a DoS vulnerability in LoopVideoBlockEPSS 0.5%CVE-2025-2820MEDIUMDenial of ServiceEPSS 0.5%CVE-2017-12190—The bio_map_user_iov and bio_unmap_user functions in block/bio.c in the Linux kernel before 4.13.8 do unbalanced refcounting when a SCSI I/OEPSS 0.5%CVE-2025-6492MEDIUMMarkText index.js getRecommendTitleFromMarkdownString redosEPSS 0.5%