Fallos del tipo CWE-400

3034 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2024-35221MEDIUMDenial of service when publishing a package on rubygems.orgEPSS 0.5%CVE-2026-46910CRITICALVulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security). SupportedEPSS 0.5%CVE-2026-6022HIGHUncontrolled Resource Consumption Vulnerability in Telerik UI for ASP.NET AJAXEPSS 0.5%CVE-2026-61155CRITICALVulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge). The supported version EPSS 0.5%CVE-2026-54340HIGHh2o has HTTP/2 state amplificationEPSS 0.5%CVE-2024-21126MEDIUMVulnerability in the Oracle Database Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 19.EPSS 0.5%CVE-2026-82260HIGHSvelteKit before 2.52.2 Memory Exhaustion via Remote Form DeserializationEPSS 0.5%CVE-2026-82261HIGHSvelteKit before 2.52.2 CPU Exhaustion via Remote Form DeserializationEPSS 0.5%CVE-2023-5333MEDIUM Denial of Service via multiple identical User IDs in /api/v4/users/idsEPSS 0.5%CVE-2026-50889HIGHAn input handling flaw in the HTTP refresh token process of LLDAP v0.6.2 allows attackers to cause a Denial of Service (DoS) via sending a cEPSS 0.5%CVE-2023-53873HIGHSyncBreeze 15.2.24 Denial of Service via Login Endpoint OverflowEPSS 0.5%CVE-2026-89425HIGHjackson-core: UTF8DataInputJsonParser._reportInvalidToken() does not honor maxErrorTokenLength, allowing unbounded StringBuilder growthEPSS 0.5%CVE-2026-36957HIGHDbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router V1.0.0 is vulnerable to Denial of Service via the boa web server URI handler. By initiatinEPSS 0.5%CVE-2026-36958HIGHA denial-of-service vulnerability exists in the U-SPEED N300 V1.0.0 wireless router. By sending a large number of concurrent HTTP requests tEPSS 0.5%CVE-2024-39548HIGHJunos OS Evolved: Receipt of specific packets in the aftmand process will lead to a memory leakEPSS 0.5%CVE-2024-48989HIGHA vulnerability in the PROFINET stack implementation of the IndraDrive (all versions) of Bosch Rexroth allows an attacker to cause a denial EPSS 0.5%CVE-2024-3508MEDIUMBzip2: compressed content bomb leads to denial of service of bombastic apiEPSS 0.5%CVE-2025-50101MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.EPSS 0.5%CVE-2025-52887HIGHcpp-httplib has unlimited number of http header fields, which causes memory leakEPSS 0.5%CVE-2026-17078MEDIUMIBM i is Affected By A Denial of Service Vulnerability in DRDA / DDM []EPSS 0.5%