Fallos del tipo CWE-400

3034 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2026-15310LOWzipfile: bzip2/LZMA/Zstandard members decompress without a max_length bound, defeating chunked-read memory limitsEPSS 0.5%CVE-2025-69873LOWajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is enaEPSS 0.5%CVE-2026-56846HIGHA flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion. ThiEPSS 0.5%CVE-2026-42212HIGHSolidCAM-GPPL-IDE: XML External Entity (XXE) and billion-laughs DoS in VMID parserEPSS 0.5%CVE-2026-65410HIGHThe issue was addressed with improved checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, mEPSS 0.5%CVE-2023-5330MEDIUM Denial of Service via Opengraph Data CacheEPSS 0.5%CVE-2024-12698MEDIUMOse-olm-catalogd-container: incomplete fix for rapid reset (cve-2023-39325/cve-2023-44487)EPSS 0.5%CVE-2024-57076HIGHA prototype pollution in the lib.post function of ajax-request v1.2.3 allows attackers to cause a Denial of Service (DoS) via supplying a crEPSS 0.5%CVE-2025-61025HIGHAn issue in the sslr_qst_get component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via craftEPSS 0.5%CVE-2020-36872HIGHBACnet Test Server 1.01 Malformed BVLC Length DoSEPSS 0.5%CVE-2026-91867MEDIUMApache Neethi: Remote policy fetch lacks a total timeout, allowing a slow server to hang the request indefinitelyEPSS 0.5%CVE-2024-57081HIGHA prototype pollution in the lib.fromQuery function of underscore-contrib v0.3.0 allows attackers to cause a Denial of Service (DoS) via supEPSS 0.5%CVE-2025-71031HIGHWater-Melon Melon commit 9df9292 and below is vulnerable to Denial of Service. The HTTP component doesn't have any maximum length. As a resuEPSS 0.5%CVE-2020-1687MEDIUMJunos OS: EX4300-MP/EX4600/QFX5K Series: High CPU load due to receipt of specific layer 2 frames in EVPN-VXLAN deployment.EPSS 0.5%CVE-2023-34109MEDIUMUser input results in Unbounded resource consumption in @zxcvbn-ts/coreEPSS 0.5%CVE-2026-26937MEDIUMUncontrolled Resource Consumption in Kibana Leading to Denial of ServiceEPSS 0.5%CVE-2025-50102MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.EPSS 0.5%CVE-2025-59471MEDIUMA denial of service vulnerability exists in self-hosted Next.js applications that have `remotePatterns` configured for the Image Optimizer. EPSS 0.5%CVE-2026-46910CRITICALVulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security). SupportedEPSS 0.5%CVE-2024-58306HIGHminaliC 2.0.0 Denial of Service Vulnerability via Large GET RequestEPSS 0.5%