Falhas do tipo CWE-400

2.995 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2023-26433MEDIUMWhen adding an external mail account, processing of IMAP "capabilities" responses are not limited to plausible sizes. Attacker with access tEPSS 1.1%CVE-2021-23215An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could EPSS 1.1%CVE-2023-26434MEDIUMWhen adding an external mail account, processing of POP3 "capabilities" responses are not limited to plausible sizes. Attacker with access tEPSS 1.1%CVE-2020-5423HIGHCloud Controller is vulnerable to denial of service via YAML parsingEPSS 1.1%CVE-2020-8123A denial of service exists in strapi v3.0.0-beta.18.3 and earlier that can be abused in the admin console using admin rights can lead to arbEPSS 1.1%CVE-2021-1266MEDIUMCisco Managed Services Accelerator Denial of Service VulnerabilityEPSS 1.1%CVE-2026-49799MEDIUMWindows Local Security Authority Subsystem Service (LSASS) Denial of Service VulnerabilityEPSS 1.1%CVE-2022-29177MEDIUMDoS via malicious p2p message in Go-EthereumEPSS 1.1%CVE-2026-21637MEDIUMA flaw in Node.js TLS error handling allows remote attackers to crash or exhaust resources of a TLS server when `pskCallback` or `ALPNCallbaEPSS 1.1%CVE-2022-31803MEDIUMCODESYS Gateway Server V2 prone to Denial of Service AttackEPSS 1.1%CVE-2023-34104HIGHRegex Injection via Doctype EntitiesEPSS 1.1%CVE-2022-48748HIGHnet: bridge: vlan: fix memory leak in __allowed_ingressEPSS 1.1%CVE-2024-27812HIGHA logic issue was addressed with improved file handling. This issue is fixed in visionOS 1.2. Processing web content may lead to a denial-ofEPSS 1.1%CVE-2021-31405HIGHRegular expression denial of service (ReDoS) in EmailField component in Vaadin 14 and 15-17EPSS 1.1%CVE-2023-31409MEDIUMUncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 112252EPSS 1.1%CVE-2017-16111The content module is a module to parse HTTP Content-* headers. It is used by the hapijs framework to provide this functionality. The moduleEPSS 1.1%CVE-2022-39271HIGHTraefik HTTP/2 connections management could cause a denial of serviceEPSS 1.1%CVE-2023-20863MEDIUMIn spring framework versions prior to 5.2.24 release+ ,5.3.27+ and 6.0.8+ , it is possible for a user to provide a specially crafted SpEL exEPSS 1.1%CVE-2023-40591HIGHDenial of service via malicious p2p message in go-ethereumEPSS 1.1%CVE-2022-21155HIGHFernhill SCADA Uncontrolled Resource ConsumptionEPSS 1.1%