Falhas do tipo CWE-400

2.951 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2017-16113The parsejson module is vulnerable to regular expression denial of service when untrusted user input is passed into it to be parsed.EPSS 1.5%CVE-2020-3132MEDIUMCisco Email Security Appliance Shortened URL Denial of Service VulnerabilityEPSS 1.5%CVE-2022-29243MEDIUMImproper input-size validation on the user new session name in Nextcloud ServerEPSS 1.5%CVE-2022-44571There is a denial of service vulnerability in the Content-Disposition parsingcomponent of Rack fixed in 2.0.9.2, 2.1.4.2, 2.2.4.1, 3.0.0.1. EPSS 1.5%CVE-2017-16115The timespan module is vulnerable to regular expression denial of service. Given 50k characters of untrusted user input it will block the evEPSS 1.5%CVE-2021-21369MEDIUMPotential DoS in Besu HTTP JSON-RPC APIEPSS 1.5%CVE-2021-1378MEDIUMCisco StarOS Denial of Service VulnerabilityEPSS 1.5%CVE-2019-13926A vulnerability has been identified in SCALANCE S602 (All versions >= V3.0 and < V4.1), SCALANCE S612 (All versions >= V3.0 and < V4.1), SCAEPSS 1.5%CVE-2025-25293HIGHruby-saml vulnerable to Remote Denial of Service (DoS) with compressed SAML responsesEPSS 1.5%CVE-2020-8136Prototype pollution vulnerability in fastify-multipart < 1.0.5 allows an attacker to crash fastify applications parsing multipart requests bEPSS 1.5%CVE-2021-47295HIGHnet: sched: fix memory leak in tcindex_partial_destroy_workEPSS 1.5%CVE-2024-39908MEDIUMDenial of service in REXMLEPSS 1.5%CVE-2020-14522HIGHSofting Industrial Automation OPCEPSS 1.5%CVE-2020-29490HIGHDell EMC Unity, Unity XT, and UnityVSA versions prior to 5.0.4.0.5.012 contain a Denial of Service vulnerability on NAS Servers with NFS expEPSS 1.5%CVE-2018-16486A prototype pollution vulnerability was found in defaults-deep <=0.2.4 that would allow a malicious user to inject properties onto Object.prEPSS 1.5%CVE-2024-4068HIGHMemory Exhaustion in bracesEPSS 1.5%CVE-2018-6335HIGHA Malformed h2 frame can cause 'std::out_of_range' exception when parsing priority meta data. This behavior can lead to denial-of-service. TEPSS 1.5%CVE-2020-27295The affected product has uncontrolled resource consumption issues, which may allow an attacker to cause a denial-of-service condition on theEPSS 1.5%CVE-2021-21236MEDIUMRegular Expression Denial of Service in CairoSVGEPSS 1.5%CVE-2019-13946HIGHProfinet-IO (PNIO) stack versions prior V06.00 do not properly limit internal resource allocation when multiple legitimate diagnostic packagEPSS 1.5%