Falhas do tipo CWE-400

2.999 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2023-41173—AdGuard DNS before 2.2 allows remote attackers to cause a denial of service via malformed UDP packets.EPSS 0.8%CVE-2024-12074MEDIUMDenial of Service in automatic1111/stable-diffusion-webuiEPSS 0.8%CVE-2026-42154HIGHPrometheus: remote read endpoint allows denial of service via crafted snappy payloadEPSS 0.8%CVE-2026-48779HIGHws: Memory exhaustion DoS from tiny fragments and data chunksEPSS 0.8%CVE-2024-10466HIGHBy sending a specially crafted push message, a remote server could have hung the parent process, causing the browser to become unresponsive.EPSS 0.8%CVE-2020-1625MEDIUMJunos OS: Kernel memory leak in virtual-memory due to interface flapsEPSS 0.8%CVE-2022-22145—CAMS for HIS Log Server contained in the following Yokogawa Electric products is vulnerable to uncontrolled resource consumption. CENTUM CS EPSS 0.8%CVE-2023-49800HIGHDenial of service by abusing `fetchOptions.retry` in nuxt-api-partyEPSS 0.8%CVE-2023-5625MEDIUMPython-eventlet: patch regression for cve-2021-21419 in some red hat buildsEPSS 0.8%CVE-2016-10524—i18n-node-angular is a module used to interact between i18n and angular without using additional resources. A REST API endpoint that is usedEPSS 0.8%CVE-2023-27483MEDIUMfieldpath's Paved.SetValue allows growing arrays up to arbitrary sizes in crossplane-runtimeEPSS 0.8%CVE-2023-0384MEDIUMUncontrolled Resource Consuption in M-Files ServerEPSS 0.8%CVE-2022-31074MEDIUMKubeEdge Cloud AdmissionController component DoSEPSS 0.8%CVE-2024-45626MEDIUMApache James: denial of service through JMAP HTML to text conversionEPSS 0.8%CVE-2023-23296MEDIUMKorenix JetWave 4200 Series 1.3.0 and JetWave 3200 Series 1.6.0 are vulnerable to Denial of Service via /goform/formDefault.EPSS 0.8%CVE-2022-23591HIGHStack overflow in TensorflowEPSS 0.8%CVE-2024-39895MEDIUMDirectus GraphQL Field Duplication Denial of Service (DoS)EPSS 0.8%CVE-2021-0215MEDIUMJunos OS: EX Series, QFX Series, SRX Branch Series, MX Series: Memory leak in packet forwarding engine due to 802.1X authenticator port interface flapsEPSS 0.8%CVE-2025-30704MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services). Supported versions that are affected arEPSS 0.8%CVE-2022-21653MEDIUMHash collision in typelevel jawnEPSS 0.8%