Fallos del tipo CWE-400

3035 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2026-67973HIGHAn issue in the CFDP receive path of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via replaying final CFDP PDUs.EPSS 0.5%CVE-2026-44433MEDIUMQuicly is vulnerable to memory exhaustionEPSS 0.5%CVE-2026-31247HIGHDocling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks thru 2.61.0. The backend uses etree.parse() to parse XML fileEPSS 0.5%CVE-2026-67976HIGHThe Ref::SignalGen component of fprime framework v4.2.2 does not validate the safety of user-controlled parameters, allowing attackers to caEPSS 0.5%CVE-2026-9675HIGHundici WebSocket client vulnerable to denial of service via cumulative fragment bypassEPSS 0.5%CVE-2026-47479HIGHNVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource consumption. A successfuEPSS 0.5%CVE-2026-56248HIGHCapgo - Unauthenticated Denial-of-Service via audit_logs RLS PolicyEPSS 0.5%CVE-2026-30350HIGHAn issue in the /store/items/search endpoint of Agent Protocol server commit e9a89f allows attackers to cause a Denial of Service (DoS) via EPSS 0.5%CVE-2026-73568HIGHpy-libp2p: yamux connection DoS via oversized data frameEPSS 0.5%CVE-2026-62296HIGHHAPI FHIR: XHTML narrative parser unbounded recursion causes StackOverflow denial of serviceEPSS 0.5%CVE-2026-5079HIGHmulter vulnerable to Denial of Service via deeply nested field namesEPSS 0.5%CVE-2026-62295HIGHHAPI FHIR: JSON utility parser unbounded recursion causes StackOverflow denial of serviceEPSS 0.5%CVE-2026-44296HIGHDeskflow: TLS multiplexer DoS on failed `SSL_accept`EPSS 0.5%CVE-2024-51316HIGHThe Tenda TX9 V22.03.02.20 firmware has a denial of service vulnerability in the update_dev_name function of the file /goform/SetOnlineDevNaEPSS 0.5%CVE-2026-51539HIGHA Denial of Service (DoS) vulnerability exists in the receive loop of libmodbus 3.1.12 when running on Windows. The issue stems from impropeEPSS 0.5%CVE-2026-86250HIGHh3 before 2.0.1-rc.18 Denial of Service via Unbounded Chunked CookieEPSS 0.5%CVE-2026-57080HIGHNet::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustion via an uncapped peer-wire message-length prefixEPSS 0.5%CVE-2026-47249HIGHKlever-Go KVM: Hash-array amplification in P2P resolver request handlingEPSS 0.5%CVE-2026-67977HIGHAn integer overflow in the Svc::FileDownlink::SendPartial component of fprime framework v4.2.2 allows attackers to cause a Denial of ServiceEPSS 0.5%CVE-2026-52880HIGHKlever-Go: REST API slow-header connection exhaustion via Gin Engine.RunEPSS 0.5%