Fallos del tipo CWE-400

3034 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2025-11149HIGHThis affects all versions of the package node-static; all versions of the package @nubosoftware/node-static. The package fails to catch an eEPSS 0.5%CVE-2026-83606HIGHxmldom PI grammar regex ReDoS: quadratic backtracking on unterminated processing instructionsEPSS 0.5%CVE-2018-0381MEDIUMCisco Aironet 1560, 1800, 2800, and 3800 Series Access Points Denial of Service VulnerabilityEPSS 0.5%CVE-2026-83619HIGHxmldom: End-tag Whitespace-Trim Regex ReDoS — quadratic backtracking in the 0.8.x end-tag parserEPSS 0.5%CVE-2026-83612HIGHxmldom: HTML raw-text closing-tag case mismatch causes output amplificationEPSS 0.5%CVE-2026-73556MEDIUMvLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of CVE-2026-55574EPSS 0.5%CVE-2026-77354HIGHkin-openapi: Uncontrolled resource consumption in openapi3filter deepObject query parameter decodingEPSS 0.5%CVE-2026-48125MEDIUMUAParser.js: Unbounded `Sec-CH-UA-Model` parsing can trigger ReDoS in `withClientHints()`EPSS 0.5%CVE-2026-26233MEDIUMDenial of Service via HTTP/2 single packet attack on login endpointEPSS 0.5%CVE-2025-70071MEDIUMAn issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXParser.cpp, ParseVectorDataArray()EPSS 0.5%CVE-2026-18358HIGHGnome-remote-desktop: gnome-remote-desktop system-mode rdp server missing connection throttling allows unauthenticated denial of serviceEPSS 0.5%CVE-2024-8626HIGHLogix Controllers Vulnerable to Denial-of-Service VulnerabilityEPSS 0.5%CVE-2026-93309MEDIUMO-RAN-SC SMO OAM VES Collector allocation of resourcesEPSS 0.5%CVE-2026-93308MEDIUMO-RAN-SC SMO OAM VES Collector allocation of resourcesEPSS 0.5%CVE-2026-67312MEDIUMaxios 0.28.0 before 0.33.0 Denial of Service via formToJSONEPSS 0.5%CVE-2026-92356MEDIUMa2ui-project a2ui Update Components basic_functions.ts updateComponents resource consumptionEPSS 0.5%CVE-2026-29856HIGHAn issue in the VirtualHost configuration handling/parser component of aaPanel v7.57.0 allows attackers to cause a Regular Expression DenialEPSS 0.5%CVE-2026-67313MEDIUMaxios 0.28.0 before 1.18.0 Denial of Service via formDataToJSONEPSS 0.5%CVE-2024-20502MEDIUMA vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unEPSS 0.5%CVE-2024-46891MEDIUMA vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly restrict theEPSS 0.5%