Falhas do tipo CWE-400

2.995 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2021-3909MEDIUMInfinite open connection causes OctoRPKI to hang foreverEPSS 1.6%CVE-2020-6986HIGHIn all versions of Omron PLC CJ Series, an attacker can send a series of specific data packets within a short period, causing a service erroEPSS 1.6%CVE-2020-8293A missing input validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows users to store unlimited data in workflow rules causingEPSS 1.6%CVE-2020-8246Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 1EPSS 1.6%CVE-2021-24893Stars Rating < 3.5.1 - Comments Denial of ServiceEPSS 1.6%CVE-2018-16487A prototype pollution vulnerability was found in lodash <4.17.11 where the functions merge, mergeWith, and defaultsDeep can be tricked into EPSS 1.6%CVE-2026-23869HIGHA denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-parcel, react-serverEPSS 1.6%CVE-2023-23552HIGHBIG-IP Advanced WAF and ASM vulnerabilityEPSS 1.5%CVE-2024-20965MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 aEPSS 1.5%CVE-2023-39477HIGHInductive Automation Ignition ConditionRefresh Resource Exhaustion Denial-of-Service VulnerabilityEPSS 1.5%CVE-2020-26256MEDIUMDenial of service in fast-csvEPSS 1.5%CVE-2021-20298A flaw was found in OpenEXR's B44Compressor. This flaw allows an attacker who can submit a crafted file to be processed by OpenEXR, to exhauEPSS 1.5%CVE-2021-40406HIGHA denial of service vulnerability exists in the cgiserver.cgi session creation functionality of reolink RLC-410W v3.0.0.136_20121102. A specEPSS 1.5%CVE-2019-1965HIGHCisco NX-OS Software Remote Management Memory Leak Denial of Service VulnerabilityEPSS 1.5%CVE-2022-36083MEDIUMJOSE vulnerable to resource exhaustion via specifically crafted JWEEPSS 1.5%CVE-2019-15593GitLab 12.2.3 contains a security vulnerability that allows a user to affect the availability of the service through a Denial of Service attEPSS 1.5%CVE-2021-21235MEDIUMInfinite loop in parsing PNG files inEPSS 1.5%CVE-2019-12714MEDIUMCisco IC3000 Industrial Compute Gateway Denial of Service VulnerabilityEPSS 1.5%CVE-2024-53299MEDIUMApache Wicket: An attacker can intentionally trigger a memory leakEPSS 1.5%CVE-2024-24762HIGHpython-multipart vulnerable to content-type header Regular expression Denial of ServiceEPSS 1.5%