Fallos del tipo CWE-400

3034 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2025-21545HIGHVulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch). Supported versions that are afEPSS 0.5%CVE-2024-38520MEDIUMSoftEther VPN with L2TP - 2.75x AmplificationEPSS 0.5%CVE-2025-30476MEDIUMDell PowerScale InsightIQ, version 5.2, contains an uncontrolled resource consumption vulnerability. An unauthenticated attacker with remoteEPSS 0.5%CVE-2026-28874HIGHThe issue was addressed with improved checks. This issue is fixed in iOS 26.4 and iPadOS 26.4. A remote attacker may cause an unexpected appEPSS 0.5%CVE-2025-67133HIGHAn issue in Hero Motocorp Vida V1 Pro 2.0.7 allows a local attacker to cause a denial of service via the BLE componentEPSS 0.5%CVE-2026-55520HIGHProtego: Exponential backtracking ReDoS in robots.txt URL wildcard matchingEPSS 0.5%CVE-2025-6921MEDIUMRegular Expression Denial of Service (ReDoS) in huggingface/transformersEPSS 0.5%CVE-2021-44319HIGHParrot AR.Drone 1 and AR.Drone 2 are vulnerable to Denial of Service. The Parrot AR.Drone platform is vulnerable to Wi-Fi deauthentication aEPSS 0.5%CVE-2026-84833MEDIUMntegrals openbrowser Browser Agent Message Construction agent.ts resource consumptionEPSS 0.5%CVE-2026-85107MEDIUMNousResearch hermes-agent Electron Main Process main.ts resourceBufferFromUrl allocation of resourcesEPSS 0.5%CVE-2026-85585HIGHSiYuan before v3.8.2 Unbounded Memory Consumption via ControlConcurrencyEPSS 0.5%CVE-2026-33232HIGHAutoGPT: Unauthenticated DoS via Disk Space ExhaustionEPSS 0.5%CVE-2025-50094MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.42, 8.4.5 EPSS 0.5%CVE-2020-1668MEDIUMJunos OS: EX2300 Series: High CPU load due to receipt of specific multicast packets on layer 2 interfaceEPSS 0.5%CVE-2026-87908HIGHmultiparty vulnerable to Denial of Service via unbounded part-header accumulationEPSS 0.5%CVE-2023-45810MEDIUMOpenFGA denial of serviceEPSS 0.5%CVE-2026-79658HIGHEch0 before 5.0.1 Denial of Service via Accept-LanguageEPSS 0.5%CVE-2025-53023MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are 8.0.0-EPSS 0.5%CVE-2026-67855HIGHopen62541 contains a heap use-after-free in the GDS PushManagement certificate update workflow when UA_ENABLE_GDS_PUSHMANAGEMENT is enabled.EPSS 0.5%CVE-2024-1953MEDIUMMattermost versions 8.1.x before 8.1.9, 9.2.x before 9.2.5, 9.3.0, and 9.4.x before 9.4.2 fail to limit the number of role names requested fEPSS 0.5%