Falhas do tipo CWE-400

2.985 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2020-3131MEDIUMCisco Webex Teams Adaptive Cards Denial of Service VulnerabilityEPSS 2.2%CVE-2018-10632In Moxa NPort 5210, 5230, and 5232 versions 2.9 build 17030709 and prior, the amount of resources requested by a malicious actor are not resEPSS 2.2%CVE-2018-14659MEDIUMThe Gluster file system through versions 4.1.4 and 3.1.2 is vulnerable to a denial of service attack via use of the 'GF_XATTR_IOSTATS_DUMP_KEPSS 2.2%CVE-2020-26289HIGHRegular expression Denial of Service in date-and-timeEPSS 2.2%CVE-2021-3670MaxQueryDuration not honoured in Samba AD DC LDAPEPSS 2.2%CVE-2016-9367HIGHAn issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions pEPSS 2.2%CVE-2021-21274MEDIUMDenial of service attack via .well-known lookupsEPSS 2.2%CVE-2017-16138The mime module < 1.4.1, 2.0.1, 2.0.2 is vulnerable to regular expression denial of service when a mime lookup is performed on untrusted useEPSS 2.2%CVE-2022-30122A possible denial of service vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 in the multipart parsing component of Rack.EPSS 2.1%CVE-2022-24839HIGHUncontrolled Resource Consumption in org.cyberneko.html (nokogiri fork)EPSS 2.1%CVE-2021-21294HIGHUnbounded connection acceptance in http4s-blaze-serverEPSS 2.1%CVE-2026-33116HIGH.NET, .NET Framework, and Visual Studio Denial of Service VulnerabilityEPSS 2.1%CVE-2018-16472A prototype pollution attack in cached-path-relative versions <=1.0.1 allows an attacker to inject properties on Object.prototype which are EPSS 2.1%CVE-2019-14888HIGHA vulnerability was found in the Undertow HTTP server in versions before 2.0.28.SP1 when listening on HTTPS. An attacker can target the HTTPEPSS 2.1%CVE-2022-39209HIGHUncontrolled Resource Consumption in cmark-gfmEPSS 2.1%CVE-2015-9241Certain input passed into the If-Modified-Since or Last-Modified headers will cause an 'illegal access' exception to be raised. Instead of sEPSS 2.1%CVE-2025-23184MEDIUMApache CXF: Denial of Service vulnerability with temporary filesEPSS 2.1%CVE-2019-1814MEDIUMCisco Small Business 300 Series Managed Switches DHCP Denial of Service VulnerabilityEPSS 2.1%CVE-2020-11090HIGHUncontrolled Resource Consumption in Indy NodeEPSS 2.1%CVE-2021-21293HIGHUnbounded connection acceptance leads to file handle exhaustionEPSS 2.1%