Falhas do tipo CWE-770

1.838 resultados

Alocação de recursos sem limite (negação de serviço por esgotamento)

A aplicação aloca recursos (memória, conexões, arquivos, threads) a pedido de um usuário sem impor limites, permitindo que um atacante esgote todos os recursos disponíveis e derrube o serviço. É basicamente deixar a porta aberta para qualquer um encher a caixa d'água até transbordar.

Exemplo

Um servidor web que cria uma nova thread para cada requisição HTTP recebida, sem limite. Um atacante envia milhares de requisições simultâneas e esgota o pool de threads, tornando o servidor inresponsivo para usuários legítimos — é negação de serviço puro.

Como mitigar

Implemente limites rigorosos: rate limiting (requisições por IP/usuário), quotas de recursos, pool de threads/conexões com tamanho máximo, timeout em operações, e monitoramento de consumo. Valide tamanhos de entrada e rejeite alocações que excedam os limites configurados.

CVE-2022-34439MEDIUMDell PowerScale OneFS, versions 8.2.0.x-9.4.0.x contain allocation of Resources Without Limits or Throttling vulnerability. A remote unautheEPSS 0.9%CVE-2022-3480HIGHDenial-of-Service vulnerability in PHOENIX CONTACT mGuard product familyEPSS 0.9%CVE-2023-29479MEDIUMRibose RNP before 0.16.3 may hang when the input is malformed.EPSS 0.9%CVE-2024-26308MEDIUMApache Commons Compress: OutOfMemoryError unpacking broken Pack200 fileEPSS 0.9%CVE-2026-39304HIGHApache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Incorrect handling of TLSv1.3 KeyUpdate can be exploited to cause DoS via OOMEPSS 0.9%CVE-2024-35202HIGHBitcoin Core before 25.0 allows remote attackers to cause a denial of service (blocktxn message-handling assertion and node exit) by includiEPSS 0.9%CVE-2026-23538HIGHFeast: resource exhaustion via websocket endpointEPSS 0.9%CVE-2023-45130HIGHFrontier opcode SUICIDE touches too many storage values on large contractsEPSS 0.9%CVE-2024-37358HIGHApache James: denial of service through the use of IMAP literalsEPSS 0.9%CVE-2023-22739MEDIUMDiscourse subject to Allocation of Resources Without Limits or ThrottlingEPSS 0.9%CVE-2025-21543MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Packaging). Supported versions that are affected are 8.0.40 aEPSS 0.9%CVE-2026-54428HIGHApache HttpComponents Core: HPackDecoder Unlimited Header List Size Before SETTINGS ACKEPSS 0.9%CVE-2024-38534HIGHSuricata modbus: txs without responses are never freedEPSS 0.9%CVE-2024-48844HIGHDenial of Service, DoSEPSS 0.9%CVE-2024-21060MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Data Dictionary). Supported versions that are affected are 8.EPSS 0.9%CVE-2025-4820MEDIUMIncorrect congestion window growth by optimistic ACKEPSS 0.9%CVE-2025-12562HIGHAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.9%CVE-2023-25568HIGHBoxo bitswap/server: DOS unbounded persistent memory leakEPSS 0.9%CVE-2024-7983HIGHDenial of Service in open-webui/open-webuiEPSS 0.9%CVE-2023-6476MEDIUMCri-o: pods are able to break out of resource confinement on cgroupv2EPSS 0.9%