CWE-400 · 3 675 записей
Неконтролируемое потребление ресурсов
Почему это происходит?
Код, разбирающий вложенные структуры, не ограничивает глубину или размер. Небольшие входные данные могут привести к несоразмерной вычислительной нагрузке.
Уязвимый и исправленный код
Показательный учебный пример. Выделенные строки показывают, где ошибка и где исправление.
Уязвимый код
function expand(node) { return node.children.map(expand);}Исправленный код
const MAX_DEPTH = 32;function expand(node, depth = 0) { if (depth > MAX_DEPTH) throw new Error("слишком глубоко"); return node.children.map((c) => expand(c, depth + 1));}Как предотвратить
- 01Задавайте в парсерах ограничения по глубине, длине и времени.
- 02Усекайте пользовательский ввод перед записью в журнал.
- 03Установите пороги оповещений по загрузке процессора и памяти.
CVE этого класса
3 677 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
90Срочно | CVE-2023-44487Готовый эксплойт | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, assiemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · CWE-400 | Высокая7,5 | KEV | 100,0 % | 10 окт. 2023 г. |
65На этой неделе | CVE-2020-3566Готовый эксплойт | Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerabilitycisco · ios xr · CWE-400 | Высокая8,6 | KEV | 3,7 % | 29 авг. 2020 г. |
65На этой неделе | CVE-2020-3569Готовый эксплойт | Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerabilitiescisco · ios xr · CWE-400 | Высокая8,6 | KEV | 3,3 % | 22 сент. 2020 г. |
64На этой неделе | CVE-2023-38180Готовый эксплойт | .NET and Visual Studio Denial of Service Vulnerabilitymicrosoft · .net · CWE-400 | Высокая7,5 | KEV | 14,0 % | 8 авг. 2023 г. |
61На этой неделе | CVE-2011-3192Готовый эксплойт | The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a deniapache · http server · CWE-400 | Высокая7,8 | — | 98,8 % | 29 авг. 2011 г. |
61На этой неделе | CVE-2026-28318Готовый эксплойт | SolarWinds Serv-U Unauthenticated Denial of Service Vulnerabilitysolarwinds · serv-u · CWE-400 | Высокая7,5 | KEV | 1,9 % | 4 июн. 2026 г. |
60На этой неделе | CVE-2026-45498Готовый эксплойт | Microsoft Defender Denial of Service Vulnerabilitymicrosoft · defender antimalware platform · CWE-400 | Высокая7,5 | KEV | 1,3 % | 20 мая 2026 г. |
58В плане | CVE-2023-45288Proof of concept | HTTP/2 CONTINUATION flood in net/httpgo standard library · net/http · CWE-400 | Высокая7,5 | — | 92,0 % | 4 апр. 2024 г. |
56В плане | CVE-2018-1000115Готовый эксплойт | Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDPmemcached · memcached · CWE-400 | Высокая7,5 | — | 88,1 % | 5 мар. 2018 г. |
56В плане | CVE-2019-9515Эксплойта нет | Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of serviceapple · swiftnio · CWE-400 | Высокая7,5 | — | 87,4 % | 13 авг. 2019 г. |
55В плане | CVE-2019-9512Эксплойта нет | Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of serviceapple · swiftnio · CWE-400 | Высокая7,5 | — | 83,4 % | 13 авг. 2019 г. |
55В плане | CVE-2019-9514Эксплойта нет | Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of serviceapple · swiftnio · CWE-400 | Высокая7,5 | — | 82,8 % | 13 авг. 2019 г. |
55В плане | CVE-2023-50868Proof of concept | The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a dennetapp · hci baseboard management controller · CWE-400 | Высокая7,5 | — | 81,7 % | 14 февр. 2024 г. |
54В плане | CVE-2019-9513Эксплойта нет | Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of serviceapple · swiftnio · CWE-400 | Высокая7,5 | — | 81,6 % | 13 авг. 2019 г. |
54В плане | CVE-2023-28342Эксплойта нет | Zoho ManageEngine ADSelfService Plus before 6218 allows anyone to conduct a Denial-of-Service attack via the Mobile App Authentication API.zohocorp · manageengine adselfservice plus · CWE-400 | Высокая7,5 | — | 78,3 % | 5 апр. 2023 г. |
54В плане | CVE-2004-1464Готовый эксплойт | Cisco IOS 12.2(15) and earlier allows remote attackers to cause a denial of service (refused VTY (virtual terminal) connections), via a crafcisco · ios · CWE-400 | Средняя5,9 | KEV | 4,8 % | 31 дек. 2004 г. |
53В плане | CVE-2021-21341Proof of concept | XStream can cause a Denial of Servicexstream · xstream · CWE-400 | Высокая7,5 | — | 77,8 % | 22 мар. 2021 г. |
53В плане | CVE-2003-0714Готовый эксплойт | The Internet Mail Service in Exchange Server 5.5 and Exchange 2000 allows remote attackers to cause a denial of service (memory exhaustion) microsoft · exchange server · CWE-400 | Высокая7,5 | — | 77,6 % | 17 нояб. 2003 г. |
52В плане | CVE-2021-22883Эксплойта нет | Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an nodejs · node.js · CWE-400 | Высокая7,5 | — | 74,4 % | 3 мар. 2021 г. |
52В плане | CVE-2018-5390Эксплойта нет | Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can linux · linux kernel · CWE-400 | Высокая7,5 | — | 73,7 % | 6 авг. 2018 г. |
52В плане | CVE-2022-29885Proof of concept | EncryptInterceptor does not provide complete protection on insecure networksapache · tomcat · CWE-400 | Высокая7,5 | — | 73,5 % | 12 мая 2022 г. |
52В плане | CVE-2019-0199Эксплойта нет | The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.14 and 8.5.0 to 8.5.37 accepted streams with excessive numbers of SETTINGS framesapache · tomcat · CWE-400 | Высокая7,5 | — | 72,9 % | 10 апр. 2019 г. |
52В плане | CVE-2017-3144Эксплойта нет | Failure to properly clean up closed OMAPI connections can exhaust available socketsisc · dhcp · CWE-400 | Высокая7,5 | — | 72,7 % | 16 янв. 2019 г. |
52В плане | CVE-2018-6389Proof of concept | In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the large list of registwordpress · wordpress · CWE-400 | Высокая7,5 | — | 72,7 % | 6 февр. 2018 г. |
51В плане | CVE-2023-43622Proof of concept | Apache HTTP Server: DoS in HTTP/2 with initial windows size 0apache · http server · CWE-400 | Высокая7,5 | — | 70,6 % | 23 окт. 2023 г. |
- CVE-2023-4448790Срочно
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 100 %siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware10 окт. 2023 г.
- CVE-2020-356665На этой неделе
Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability
ВысокаяCVSS 8,6KEVГотовый эксплойтEPSS 4 %cisco · ios xr29 авг. 2020 г.
- CVE-2020-356965На этой неделе
Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerabilities
ВысокаяCVSS 8,6KEVГотовый эксплойтEPSS 3 %cisco · ios xr22 сент. 2020 г.
- CVE-2023-3818064На этой неделе
.NET and Visual Studio Denial of Service Vulnerability
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 14 %microsoft · .net8 авг. 2023 г.
- CVE-2011-319261На этой неделе
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a deni
ВысокаяCVSS 7,8Готовый эксплойтEPSS 99 %apache · http server29 авг. 2011 г.
- CVE-2026-2831861На этой неделе
SolarWinds Serv-U Unauthenticated Denial of Service Vulnerability
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 2 %solarwinds · serv-u4 июн. 2026 г.
- CVE-2026-4549860На этой неделе
Microsoft Defender Denial of Service Vulnerability
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 1 %microsoft · defender antimalware platform20 мая 2026 г.
- CVE-2023-4528858В плане
HTTP/2 CONTINUATION flood in net/http
ВысокаяCVSS 7,5Proof of conceptEPSS 92 %go standard library · net/http4 апр. 2024 г.
- CVE-2018-100011556В плане
Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDP
ВысокаяCVSS 7,5Готовый эксплойтEPSS 88 %memcached · memcached5 мар. 2018 г.
- CVE-2019-951556В плане
Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service
ВысокаяCVSS 7,5Эксплойта нетEPSS 87 %apple · swiftnio13 авг. 2019 г.
- CVE-2019-951255В плане
Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service
ВысокаяCVSS 7,5Эксплойта нетEPSS 83 %apple · swiftnio13 авг. 2019 г.
- CVE-2019-951455В плане
Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service
ВысокаяCVSS 7,5Эксплойта нетEPSS 83 %apple · swiftnio13 авг. 2019 г.
- CVE-2023-5086855В плане
The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a den
ВысокаяCVSS 7,5Proof of conceptEPSS 82 %netapp · hci baseboard management controller14 февр. 2024 г.
- CVE-2019-951354В плане
Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service
ВысокаяCVSS 7,5Эксплойта нетEPSS 82 %apple · swiftnio13 авг. 2019 г.
- CVE-2023-2834254В плане
Zoho ManageEngine ADSelfService Plus before 6218 allows anyone to conduct a Denial-of-Service attack via the Mobile App Authentication API.
ВысокаяCVSS 7,5Эксплойта нетEPSS 78 %zohocorp · manageengine adselfservice plus5 апр. 2023 г.
- CVE-2004-146454В плане
Cisco IOS 12.2(15) and earlier allows remote attackers to cause a denial of service (refused VTY (virtual terminal) connections), via a craf
СредняяCVSS 5,9KEVГотовый эксплойтEPSS 5 %cisco · ios31 дек. 2004 г.
- CVE-2021-2134153В плане
XStream can cause a Denial of Service
ВысокаяCVSS 7,5Proof of conceptEPSS 78 %xstream · xstream22 мар. 2021 г.
- CVE-2003-071453В плане
The Internet Mail Service in Exchange Server 5.5 and Exchange 2000 allows remote attackers to cause a denial of service (memory exhaustion)
ВысокаяCVSS 7,5Готовый эксплойтEPSS 78 %microsoft · exchange server17 нояб. 2003 г.
- CVE-2021-2288352В плане
Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an
ВысокаяCVSS 7,5Эксплойта нетEPSS 74 %nodejs · node.js3 мар. 2021 г.
- CVE-2018-539052В плане
Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can
ВысокаяCVSS 7,5Эксплойта нетEPSS 74 %linux · linux kernel6 авг. 2018 г.
- CVE-2022-2988552В плане
EncryptInterceptor does not provide complete protection on insecure networks
ВысокаяCVSS 7,5Proof of conceptEPSS 73 %apache · tomcat12 мая 2022 г.
- CVE-2019-019952В плане
The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.14 and 8.5.0 to 8.5.37 accepted streams with excessive numbers of SETTINGS frames
ВысокаяCVSS 7,5Эксплойта нетEPSS 73 %apache · tomcat10 апр. 2019 г.
- CVE-2017-314452В плане
Failure to properly clean up closed OMAPI connections can exhaust available sockets
ВысокаяCVSS 7,5Эксплойта нетEPSS 73 %isc · dhcp16 янв. 2019 г.
- CVE-2018-638952В плане
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the large list of regist
ВысокаяCVSS 7,5Proof of conceptEPSS 73 %wordpress · wordpress6 февр. 2018 г.
- CVE-2023-4362251В плане
Apache HTTP Server: DoS in HTTP/2 with initial windows size 0
ВысокаяCVSS 7,5Proof of conceptEPSS 71 %apache · http server23 окт. 2023 г.