Falhas do tipo CWE-400

2.995 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2024-10599MEDIUMTongda OA 2017 package_static_resources.php resource consumptionEPSS 1.0%CVE-2024-32476MEDIUMDenial of Service via malicious jqPathExpressions in ignoreDifferencesEPSS 1.0%CVE-2021-22101Cloud Controller versions prior to 1.118.0 are vulnerable to unauthenticated denial of Service(DoS) vulnerability allowing unauthenticated aEPSS 1.0%CVE-2021-28510MEDIUMFor certain systems running EOS, a Precision Time Protocol (PTP) packet of a management/signaling message with an invalid Type-Length-Value (TLV) causes the PTP agent to restart. Repeated restarts of the service will make the service unavailable.EPSS 1.0%CVE-2021-29453MEDIUMDenial of service through memory exhaustionEPSS 1.0%CVE-2023-44321MEDIUMAffected devices do not properly validate the length of inputs when performing certain configuration changes in the web interface allowing aEPSS 1.0%CVE-2021-22139Kibana versions before 7.12.1 contain a denial of service vulnerability was found in the webhook actions due to a lack of timeout or a limitEPSS 1.0%CVE-2024-3789MEDIUMUncontrolled Resource Consumption vulnerability in WBSAirbackEPSS 1.0%CVE-2022-43740HIGHIBM Security Verify Access denial of serviceEPSS 1.0%CVE-2022-2053When a POST request comes through AJP and the request exceeds the max-post-size limit (maxEntitySize), Undertow's AjpServerRequestConduit imEPSS 1.0%CVE-2024-21051MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.34 and priEPSS 1.0%CVE-2023-3153MEDIUMService monitor mac flow is not rate limitedEPSS 1.0%CVE-2023-1605HIGHDenial of Service in radareorg/radare2EPSS 1.0%CVE-2026-42587HIGHNetty: HttpContentDecompressor maxAllocation bypass via Content-Encoding: br/zstd/snappy enables decompression bomb DoSEPSS 1.0%CVE-2022-27507MEDIUMAuthenticated denial of service EPSS 1.0%CVE-2024-1309MEDIUMResource Consumption Identified in NTP before 4.2.4p8 and 4.2.5EPSS 1.0%CVE-2021-31340A vulnerability has been identified in SIMATIC RF166C (All versions > V1.1 and < V1.3.2), SIMATIC RF185C (All versions > V1.1 and < V1.3.2),EPSS 1.0%CVE-2024-21050MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.34 and priEPSS 1.0%CVE-2022-2004HIGHAutomationDirect DirectLOGIC with Ethernet Communication Uncontrolled Resource ConsumptionEPSS 1.0%CVE-2022-3613MEDIUMAn issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 before 15.6.4, all versioEPSS 1.0%