Falhas do tipo CWE-400

2.995 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2021-1489MEDIUMCisco Firepower Device Manager Software Filesystem Space Exhaustion Denial of Service VulnerabilityEPSS 1.2%CVE-2017-7935A Resource Exhaustion issue was discovered in Phoenix Contact GmbH mGuard firmware versions 8.3.0 to 8.4.2. An attacker may compromise the dEPSS 1.2%CVE-2024-1765MEDIUMUnlimited resource allocation by QUIC CRYPTO frames flooding in quicheEPSS 1.2%CVE-2021-32617MEDIUMDenial of service in Exiv2EPSS 1.2%CVE-2026-58627HIGHWindows DHCP Server Denial of Service VulnerabilityEPSS 1.2%CVE-2026-50653HIGHAzure Active Directory Denial of Service VulnerabilityEPSS 1.2%CVE-2023-26104HIGHAll versions of the package lite-web-server are vulnerable to Denial of Service (DoS) when an attacker sends an HTTP request and includes coEPSS 1.2%CVE-2023-5915A vulnerability of Uncontrolled Resource Consumption has been identified in STARDOM provided by Yokogawa Electric Corporation. This vulnerabEPSS 1.2%CVE-2017-16030Useragent is used to parse useragent headers. It uses several regular expressions to accomplish this. An attacker could edit their own headeEPSS 1.2%CVE-2021-41118MEDIUMReDoS in DynamicPageList3EPSS 1.2%CVE-2025-46727HIGHUnbounded-Parameter DoS in Rack::QueryParserEPSS 1.2%CVE-2020-8192A denial of service vulnerability exists in Fastify v2.14.1 and v3.0.0-rc.4 that allows a malicious user to trigger resource exhaustion (wheEPSS 1.2%CVE-2021-0229MEDIUMJunos OS: Receipt of specific packets could lead to Denial of Service in MQTT ServerEPSS 1.2%CVE-2023-29449MEDIUMLimited control of resource utilization in JS preprocessingEPSS 1.2%CVE-2015-9239ansi2html is vulnerable to regular expression denial of service (ReDoS) when certain types of user input is passed in.EPSS 1.2%CVE-2016-10520jadedown is vulnerable to regular expression denial of service (ReDoS) when certain types of user input is passed in.EPSS 1.2%CVE-2022-21700MEDIUMMemory leak in micronaut-coreEPSS 1.1%CVE-2022-20692HIGHCisco IOS XE Software NETCONF Over SSH Denial of Service VulnerabilityEPSS 1.1%CVE-2017-2680HIGHSpecially crafted PROFINET DCP broadcast packets could cause a denial of service condition of affected products on a local Ethernet segment EPSS 1.1%CVE-2023-26432MEDIUMWhen adding an external mail account, processing of SMTP "capabilities" responses are not limited to plausible sizes. Attacker with access tEPSS 1.1%