Falhas do tipo CWE-400

2.994 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2023-22796A regular expression based DoS vulnerability in Active Support <6.1.7.1 and <7.0.4.1. A specially crafted string passed to the underscore meEPSS 1.7%CVE-2020-8237Prototype pollution in json-bigint npm package < 1.0.0 may lead to a denial-of-service (DoS) attack.EPSS 1.7%CVE-2019-0031HIGHJunos OS: jdhcpd daemon memory consumption Denial of Service when receiving specific IPv6 DHCP packets.EPSS 1.7%CVE-2019-13940MEDIUMA vulnerability has been identified in SIMATIC ET 200pro IM154-8 PN/DP CPU (All versions < V3.X.17), SIMATIC ET 200pro IM154-8F PN/DP CPU (AEPSS 1.7%CVE-2024-23952MEDIUMApache Superset: Allows for uncontrolled resource consumption via a ZIP bomb (version range fix for CVE-2023-46104)EPSS 1.7%CVE-2023-22792HIGHA regular expression based DoS vulnerability in Action Dispatch <6.0.6.1,< 6.1.7.1, and <7.0.4.1. Specially crafted cookies, in combination EPSS 1.7%CVE-2021-20237An uncontrolled resource consumption (memory leak) flaw was found in ZeroMQ's src/xpub.cpp in versions before 4.3.3. This flaw allows a remoEPSS 1.7%CVE-2019-10162LOWA vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.10, 4.0.8 allowing an authorized user to cause the serveEPSS 1.7%CVE-2017-6043A Resource Consumption issue was discovered in Trihedral VTScada Versions prior to 11.2.26. The client does not properly validate the input EPSS 1.7%CVE-2021-41167HIGHUnlimited requests in modern-asyncEPSS 1.7%CVE-2018-16469The merge.recursive function in the merge package <1.2.1 can be tricked into adding or modifying properties of the Object prototype. These pEPSS 1.7%CVE-2021-3690A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attackEPSS 1.7%CVE-2019-19281A vulnerability has been identified in SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions >= V2.5 and < VEPSS 1.7%CVE-2021-29469MEDIUMPotential exponential regex in monitor modeEPSS 1.7%CVE-2021-31409HIGHServer session is not invalidated when logout() helper method of Authentication module is used in Vaadin 18-19EPSS 1.7%CVE-2023-46104MEDIUMApache Superset: Allows for uncontrolled resource consumption via a ZIP bombEPSS 1.7%CVE-2021-21391MEDIUMRegular expression Denial of Service in multiple packagesEPSS 1.7%CVE-2020-15783HIGHA vulnerability has been identified in SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions), SIMATIC TDC EPSS 1.7%CVE-2025-26677HIGHWindows Remote Desktop Gateway (RD Gateway) Denial of Service VulnerabilityEPSS 1.7%CVE-2017-16116The string module is a module that provides extra string operations. The string module is vulnerable to regular expression denial of serviceEPSS 1.7%