Fallos del tipo CWE-400

3036 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2026-31247HIGHDocling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks thru 2.61.0. The backend uses etree.parse() to parse XML fileEPSS 0.5%CVE-2026-31958HIGHTornado has a DoS due to too many multipart partsEPSS 0.5%CVE-2026-94449HIGHQuarkus-smallrye-fault-tolerance: quarkus-smallrye-fault-tolerance: memory leak in @applyguard leads to denial of serviceEPSS 0.5%CVE-2026-48208MEDIUMDenial-of-Service via SVG Rendering in TicketEPSS 0.5%CVE-2025-24235MEDIUMA memory initialization issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, mEPSS 0.5%CVE-2026-41324HIGHbasic-ftp vulnerable to denial of service via unbounded memory consumption in Client.list()EPSS 0.5%CVE-2026-89147HIGHNet-SNMP through 5.9.5.2 Denial of Service via Blocking Unauthenticated SMUX ReadEPSS 0.5%CVE-2026-42583HIGHNetty: Lz4FrameDecoder resource exhaustionEPSS 0.5%CVE-2026-33375MEDIUMGrafana MSSQL Data Source Plugin: Restriction Bypass Leading to OOM DoSEPSS 0.5%CVE-2025-50095MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 9.0.0-9.EPSS 0.5%CVE-2023-33958MEDIUMDefault `maxSignatureAttempts` in `notation verify` enables an endless data attack in notationEPSS 0.5%CVE-2025-55521MEDIUMAn issue in the component /settings/localisation of Akaunting v3.1.18 allows authenticated attackers to cause a Denial of Service (DoS) via EPSS 0.5%CVE-2024-53693HIGHQTS, QuTS heroEPSS 0.5%CVE-2025-9465HIGHArmorStart® LT - Multiple Denial-of-Service VulnerabilitiesEPSS 0.5%CVE-2025-26481HIGHDell PowerScale OneFS, versions 9.4.0.0 through 9.9.0.0, contains an uncontrolled resource consumption vulnerability. A remote unprivileged EPSS 0.5%CVE-2024-56921HIGHAn issue was discovered in Open5gs v2.7.2. InitialUEMessage, Registration request sent at a specific time can crash AMF due to incorrect errEPSS 0.5%CVE-2025-52961HIGHJunos OS Evolved: PTX Series except PTX10003: An unauthenticated adjacent attacker sending specific valid traffic can cause a memory leak in cfmman leading to FPC crash and restartEPSS 0.5%CVE-2024-44160HIGHA buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7, macOS VentuEPSS 0.5%CVE-2025-25374HIGHIn NASA cFS (Core Flight System) Aquila, it is possible to put the onboard software in a state that will prevent the launch of any external EPSS 0.5%CVE-2025-10932HIGHAS2 module allows uncontrolled file uploadsEPSS 0.5%