Falhas do tipo CWE-770

1.846 resultados

Alocação de recursos sem limite (negação de serviço por esgotamento)

A aplicação aloca recursos (memória, conexões, arquivos, threads) a pedido de um usuário sem impor limites, permitindo que um atacante esgote todos os recursos disponíveis e derrube o serviço. É basicamente deixar a porta aberta para qualquer um encher a caixa d'água até transbordar.

Exemplo

Um servidor web que cria uma nova thread para cada requisição HTTP recebida, sem limite. Um atacante envia milhares de requisições simultâneas e esgota o pool de threads, tornando o servidor inresponsivo para usuários legítimos — é negação de serviço puro.

Como mitigar

Implemente limites rigorosos: rate limiting (requisições por IP/usuário), quotas de recursos, pool de threads/conexões com tamanho máximo, timeout em operações, e monitoramento de consumo. Valide tamanhos de entrada e rejeite alocações que excedam os limites configurados.

CVE-2024-33495HIGHA vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating ManageEPSS 0.6%CVE-2022-4045LOWAuthenticated user could send multiple requests containing a parameter which could fetch a large amount of data and can crash a Mattermost serverEPSS 0.6%CVE-2026-1168HIGHAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.6%CVE-2024-13054MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.6%CVE-2026-15007MEDIUMDenial of service vulnerability in GitHub Enterprise Server allowed service disruption via deeply nested YAML in release notes configurationEPSS 0.6%CVE-2025-14871HIGHAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.6%CVE-2023-39269HIGHA vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i800NC, RUGGEDCOM i801, RUGGEDCOM i801NC, RUGGEDCOM i802, RUGGEDCOM i802NC,EPSS 0.6%CVE-2023-38684MEDIUMDiscourse vulnerable to ossible DDoS due to unbounded limits in various controller actionsEPSS 0.6%CVE-2024-58339HIGHLlamaIndex <= 0.12.2 VannaQueryEngine SQL Execution Allows Resource ExhaustionEPSS 0.6%CVE-2024-52920HIGHBitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (infinite loop) via a malformed GETDATA message.EPSS 0.6%CVE-2022-46159MEDIUMAny authenticated Discourse user can create an unlisted topicEPSS 0.6%CVE-2024-2874MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.6%CVE-2025-0189HIGHDenial of Service in aimhubio/aimEPSS 0.6%CVE-2022-4723MEDIUMAllocation of Resources Without Limits or Throttling in ikus060/rdiffwebEPSS 0.6%CVE-2024-1066MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.6%CVE-2025-25186MEDIUMNet::IMAP vulnerable to possible DoS by memory exhaustionEPSS 0.6%CVE-2026-40983HIGHMicrometer gRPC server instrumentation DoS vulnerabilityEPSS 0.6%CVE-2026-49866HIGHlibp2p: CPU DoS via oversized IHAVE and IWANT control message arraysEPSS 0.6%CVE-2024-7807HIGHDenial of Service (DOS) in gaizhenbiao/chuanhuchatgptEPSS 0.6%CVE-2026-49851HIGHMistune: Potential DoS via quadratic-time parsing in parse_link_textEPSS 0.6%