Falhas do tipo CWE-400

2.967 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2020-25242A vulnerability has been identified in SIMATIC NET CP 343-1 Advanced (incl. SIPLUS variants) (All versions), SIMATIC NET CP 343-1 Lean (inclEPSS 1.3%CVE-2023-47633HIGHUncontrolled Resource Consumption in TraefikEPSS 1.3%CVE-2022-44566HIGHA denial of service vulnerability present in ActiveRecord's PostgreSQL adapter <7.0.4.1 and <6.1.7.1. When a value outside the range for a 6EPSS 1.3%CVE-2022-22556LOWDell PowerStore contains an Uncontrolled Resource Consumption Vulnerability in PowerStore User Interface. A remote unauthenticated attacker EPSS 1.3%CVE-2026-55440MEDIUMMicrosoft UFO: COMMAND_RESULTS handler creates unowned sessions, allowing authenticated session-squatting denial of serviceEPSS 1.3%CVE-2022-3257LOWServer-side Denial of Service while processing a specifically crafted GIF fileEPSS 1.3%CVE-2022-4896HIGHCyber Control, in its 1.650 version, is affected by a vulnerability in the generation on the server of pop-up windows with the messages "PNTEPSS 1.3%CVE-2024-23450MEDIUMElasticsearch Uncontrolled Resource Consumption vulnerabilityEPSS 1.3%CVE-2026-45769HIGHikev2: unbounded client transform storage can lead to resource exhaustionEPSS 1.3%CVE-2024-24814HIGHDenial of service when manipulating mod_auth_openidc_session_chunks cookie in mod_auth_openidcEPSS 1.3%CVE-2018-17898Yokogawa STARDOM Controllers FCJ,FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The controller application fails to prevent memoryEPSS 1.3%CVE-2022-3411MEDIUMA lack of length validation in GitLab CE/EE affecting all versions from 12.4 before 15.6.7, 15.7 before 15.7.6, and 15.8 before 15.8.1 allowEPSS 1.2%CVE-2020-1722MEDIUMA flaw was found in all ipa versions 4.x.x through 4.8.0. When sending a very long password (>= 1,000,000 characters) to the server, the pasEPSS 1.2%CVE-2022-21708MEDIUMDenial of Service in graphql-goEPSS 1.2%CVE-2023-1733MEDIUMA denial of service condition exists in the Prometheus server bundled with GitLab affecting all versions from 11.10 to 15.8.5, 15.9 to 15.9.EPSS 1.2%CVE-2020-3306MEDIUMCisco Adaptive Security Appliance Software and Firepower Threat Defense Software DHCP Denial of Service VulnerabilityEPSS 1.2%CVE-2020-3305MEDIUMCisco Adaptive Security Appliance Software and Firepower Threat Defense Software BGP Denial of Service VulnerabilityEPSS 1.2%CVE-2018-10864MEDIUMAn uncontrolled resource consumption flaw has been discovered in redhat-certification in the way documents are loaded. A remote attacker mayEPSS 1.2%CVE-2023-2263HIGHRockwell Automation Kinetix 5700 DC Bus Power Supply Series A – CIP Message Attack Could Cause Denial-Of-ServiceEPSS 1.2%CVE-2020-14326A vulnerability was found in RESTEasy, where RootNode incorrectly caches routes. This issue results in hash flooding, leading to slower requEPSS 1.2%