Fallos del tipo CWE-400

3034 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2026-17078MEDIUMIBM i is Affected By A Denial of Service Vulnerability in DRDA / DDM []EPSS 0.5%CVE-2024-10344HIGHUnauthenticated Denial of Service via Refuse FunctionEPSS 0.5%CVE-2025-43857MEDIUMnet-imap rubygem vulnerable to possible DoS by memory exhaustionEPSS 0.5%CVE-2025-52887HIGHcpp-httplib has unlimited number of http header fields, which causes memory leakEPSS 0.5%CVE-2024-10345HIGHUnauthenticated Denial of Service via Shutdown FunctionEPSS 0.5%CVE-2024-10314HIGHUnauthenticated Denial of Service via Auto Generation FunctionEPSS 0.5%CVE-2025-54995MEDIUMAsterisk remotely exploitable leak of RTP UDP ports and internal resourcesEPSS 0.5%CVE-2024-20526MEDIUMA vulnerability in the SSH server of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cauEPSS 0.5%CVE-2026-20650HIGHA denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26EPSS 0.5%CVE-2026-73568HIGHpy-libp2p: yamux connection DoS via oversized data frameEPSS 0.5%CVE-2026-9675HIGHundici WebSocket client vulnerable to denial of service via cumulative fragment bypassEPSS 0.5%CVE-2026-50125HIGHMKP: Unbounded Pod Log Read via Attacker-Controlled `limitBytes`/`tailLines` Causes Memory ExhaustionEPSS 0.5%CVE-2026-47249HIGHKlever-Go KVM: Hash-array amplification in P2P resolver request handlingEPSS 0.5%CVE-2026-62295HIGHHAPI FHIR: JSON utility parser unbounded recursion causes StackOverflow denial of serviceEPSS 0.5%CVE-2026-31247HIGHDocling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks thru 2.61.0. The backend uses etree.parse() to parse XML fileEPSS 0.5%CVE-2026-94449HIGHQuarkus-smallrye-fault-tolerance: quarkus-smallrye-fault-tolerance: memory leak in @applyguard leads to denial of serviceEPSS 0.5%CVE-2026-40007HIGHApache IoTDB: Unauthenticated unbounded recursion in IoTDB AirGap receiver's E-language prefix parser causes per-connection StackOverflowErrorEPSS 0.5%CVE-2026-31958HIGHTornado has a DoS due to too many multipart partsEPSS 0.5%CVE-2026-44296HIGHDeskflow: TLS multiplexer DoS on failed `SSL_accept`EPSS 0.5%CVE-2026-44892HIGHNetty has a Vulnerable Default Configuration Which Leads to Denial of Service via Unbounded HTTP/3 Header SizeEPSS 0.5%