Fallos del tipo CWE-400

3036 resultados

Consumo descontrolado de recursos (esgotamento)

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições do usuário ou eventos externos. Um atacante explora isso enviando muitas requisições ou dados grandes para derrubar o serviço, indisponibilizando-o para usuários legítimos.

Ejemplo

Um endpoint de upload aceita arquivos sem limitar o tamanho ou taxa de envio; um atacante manda gigabytes contínuos até a aplicação ficar sem espaço em disco ou memória. Ou um loop sem condição de parada processa dados de entrada indefinidamente, travando a CPU.

Cómo mitigar

Implemente limites explícitos: tamanho máximo de arquivo/requisição, rate limiting (requisições por IP/usuário), timeouts, pool de conexões com tamanho fixo, e monitoramento de recursos. Valide e rejeite early entradas que excedem esses limites.

CVE-2024-30915MEDIUMAn issue was discovered in OpenDDS commit b1c534032bb62ad4ae32609778de6b8d6c823a66, allows a local attacker to cause a denial of service andEPSS 0.5%CVE-2026-52890HIGHWekan: Arbitrary file read and server DoS via attachment versions.original.pathEPSS 0.5%CVE-2024-39551HIGHJunos OS: SRX Series and MX Series with SPC3 and MS-MPC/MIC: Receipt of specific packets in H.323 ALG causes traffic dropEPSS 0.5%CVE-2025-53054MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.43, 8.4.0EPSS 0.5%CVE-2025-4444MEDIUMTor Onion Service Descriptor resource consumptionEPSS 0.5%CVE-2024-36845MEDIUMAn invalid pointer in the modbus_receive() function of libmodbus v3.1.6 allows attackers to cause a Denial of Service (DoS) via a crafted meEPSS 0.5%CVE-2022-23382HIGHShenzhen Hichip Vision Technology IP Camera Firmware V11.4.8.1.1-20170926 has a denial of service vulnerability through sending a crafted muEPSS 0.5%CVE-2022-48351HIGHThe secure OS module has configuration defects. Successful exploitation of this vulnerability may affect availability.EPSS 0.5%CVE-2025-48631MEDIUMIn onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhaustion. This could lead EPSS 0.5%CVE-2025-63560HIGHAn issue in KiloView Dual Channel 4k HDMI & 3G-SDI HEVC Video Encoder Firmware v.1.20.0006 allows a remote attacker to cause a denial of serEPSS 0.5%CVE-2022-28880MEDIUMDenial-of-Service (DoS) VulnerabilityEPSS 0.5%CVE-2026-56145MEDIUMUncontrolled Resource Consumption in Elasticsearch Leading to Denial of ServiceEPSS 0.5%CVE-2026-63260MEDIUMUncontrolled Resource Consumption in Kibana Leading to Denial of ServiceEPSS 0.5%CVE-2026-42400MEDIUMUncontrolled Resource Consumption in Kibana Leading to Denial of ServiceEPSS 0.5%CVE-2026-63139MEDIUMUncontrolled Resource Consumption in Kibana Leading to Denial of ServiceEPSS 0.5%CVE-2026-77755HIGHDenial of Service in MISP-STIX Import via Malformed or Oversized STIX Documents in misp-stix libraryEPSS 0.5%CVE-2026-49094MEDIUMUncontrolled Resource Consumption in Kibana Leading to Denial of ServiceEPSS 0.5%CVE-2026-33464MEDIUMUncontrolled Resource Consumption in Kibana Leading to Denial of ServiceEPSS 0.5%CVE-2026-42399MEDIUMUncontrolled Resource Consumption in Kibana Leading to Denial of ServiceEPSS 0.5%CVE-2026-63261MEDIUMUncontrolled Resource Consumption in Kibana Leading to Denial of ServiceEPSS 0.5%