Falhas do tipo CWE-400

2.982 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2020-14326A vulnerability was found in RESTEasy, where RootNode incorrectly caches routes. This issue results in hash flooding, leading to slower requEPSS 1.2%CVE-2023-2778HIGHRockwell Automation FactoryTalk Transaction Manager Vulnerable to Denial-Of-ServiceEPSS 1.2%CVE-2024-42849MEDIUMAn issue in Silverpeas v.6.4.2 and lower allows a remote attacker to cause a denial of service via the password change function.EPSS 1.2%CVE-2023-50685HIGHAn issue in Hipcam Cameras RealServer v.1.0 allows a remote attacker to cause a denial of service via a crafted script to the client_port paEPSS 1.2%CVE-2023-0518MEDIUMAn issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0 before 15.6.7, all versions starting from 15.7 beforeEPSS 1.2%CVE-2022-3759MEDIUMAn issue has been discovered in GitLab CE/EE affecting all versions starting from 14.3 before 15.6.7, all versions starting from 15.7 beforeEPSS 1.2%CVE-2017-16136method-override is a module used by the Express.js framework to let you use HTTP verbs such as PUT or DELETE in places where the client doesEPSS 1.2%CVE-2020-15114HIGHDenial of Service in etcdEPSS 1.2%CVE-2018-1107It was discovered that the is-my-json-valid JavaScript library used an inefficient regular expression to validate JSON fields defined to havEPSS 1.2%CVE-2023-49295MEDIUMquic-go's path validation mechanism can cause denial of serviceEPSS 1.2%CVE-2020-14297MEDIUMA flaw was discovered in Wildfly's EJB Client as shipped with Red Hat JBoss EAP 7, where some specific EJB transaction objects may get accumEPSS 1.2%CVE-2026-72923HIGHMicrosoft.OpenApi.YamlReader/Readers vulnerable to denial of service via YAML alias expansionEPSS 1.2%CVE-2024-41989HIGHAn issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The floatformat template filter is subject to significant memory cEPSS 1.2%CVE-2019-15584A denial of service exists in gitlab <v12.3.2, <v12.2.6, and <v12.1.10 that would let an attacker bypass input validation in markdown fieldsEPSS 1.2%CVE-2022-48474HIGHControl de Ciber, in its 1.650 version, is affected by a Denial of Service condition through the version function. Sending a malicious requeEPSS 1.2%CVE-2020-1600MEDIUMJunos OS: A specific SNMP command can trigger a high CPU usage Denial of Service in the RPD daemon.EPSS 1.2%CVE-2024-41946MEDIUMREXML DoS vulnerabilityEPSS 1.2%CVE-2026-55450CRITICALLangflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leakEPSS 1.2%CVE-2022-39278HIGHIstio vulnerable to denial of service attack due to Golang Regex LibraryEPSS 1.2%CVE-2021-1489MEDIUMCisco Firepower Device Manager Software Filesystem Space Exhaustion Denial of Service VulnerabilityEPSS 1.2%