Fallos del tipo CWE-400

3034 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2026-67855HIGHopen62541 contains a heap use-after-free in the GDS PushManagement certificate update workflow when UA_ENABLE_GDS_PUSHMANAGEMENT is enabled.EPSS 0.5%CVE-2024-54730HIGHFlatnotes <v5.3.1 is vulnerable to denial of service through the upload image function.EPSS 0.5%CVE-2026-67445MEDIUMMailpit: SMTP command parser buffers unbounded command lines before syntax rejectionEPSS 0.5%CVE-2025-65890HIGHA device-ID validation flaw in OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) by calling flow.cuda.synchronize() with anEPSS 0.5%CVE-2026-67446MEDIUMMailpit: Thumbnail generation decodes unbounded image dimensions before scalingEPSS 0.5%CVE-2026-45822MEDIUMdecode-uri-component through 0.4.1 is vulnerable to denial of service. The decode() function splits input on '%' producing N tokens and callEPSS 0.5%CVE-2026-47244MEDIUMNetty HTTP/2: Advertised MAX_CONCURRENT_STREAMS are not enforcedEPSS 0.5%CVE-2024-28053LOWResource Exhaustion via the Invitation FeatureEPSS 0.5%CVE-2018-6554—Memory leak in the irda_bind function in net/irda/af_irda.c and later in drivers/staging/irda/net/af_irda.c in the Linux kernel before 4.17 EPSS 0.5%CVE-2023-33957LOWDenial of service from high number of artifact signatures in notationEPSS 0.5%CVE-2026-34445HIGHONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings.EPSS 0.5%CVE-2026-25791HIGHSliver has a DNS C2 OTP Bypass Allows Unauthenticated Session Flooding and Denial of ServiceEPSS 0.5%CVE-2026-25579CRITICALNavidrome affected by Denial of Service and disk exhaustion via oversized `size` parameter in `/rest/getCoverArt` and `/share/img/<token>` endpointsEPSS 0.5%CVE-2024-25451MEDIUMBento4 v1.6.0-640 was discovered to contain an out-of-memory bug via the AP4_DataBuffer::ReallocateBuffer() function.EPSS 0.5%CVE-2020-1689MEDIUMJunos OS: EX4300-MP/EX4600/QFX5K Series: High CPU load due to receipt of specific layer 2 frames when deployed in a Virtual Chassis configurationEPSS 0.5%CVE-2024-23323MEDIUMExcessive CPU usage when URI template matcher is configured using regex in EnvoyEPSS 0.5%CVE-2026-45783HIGHlibp2p: Unvalidated PUT_VALUE records allow unbounded disk exhaustion on DHT server nodesEPSS 0.5%CVE-2024-4210MEDIUMUncontrolled Resource Consumption in GitLabEPSS 0.5%CVE-2025-6176HIGHBrotli decompression bomb DoS in scrapy/scrapyEPSS 0.5%CVE-2020-8557MEDIUMKubernetes node disk Denial of Service by writing to container /etc/hostsEPSS 0.5%