Falhas do tipo CWE-770

1.846 resultados

Alocação de recursos sem limite (negação de serviço por esgotamento)

A aplicação aloca recursos (memória, conexões, arquivos, threads) a pedido de um usuário sem impor limites, permitindo que um atacante esgote todos os recursos disponíveis e derrube o serviço. É basicamente deixar a porta aberta para qualquer um encher a caixa d'água até transbordar.

Exemplo

Um servidor web que cria uma nova thread para cada requisição HTTP recebida, sem limite. Um atacante envia milhares de requisições simultâneas e esgota o pool de threads, tornando o servidor inresponsivo para usuários legítimos — é negação de serviço puro.

Como mitigar

Implemente limites rigorosos: rate limiting (requisições por IP/usuário), quotas de recursos, pool de threads/conexões com tamanho máximo, timeout em operações, e monitoramento de consumo. Valide tamanhos de entrada e rejeite alocações que excedam os limites configurados.

CVE-2024-31446HIGHOpenComputers Denial of Service using xpcallEPSS 0.6%CVE-2026-50525HIGH.NET Denial of Service VulnerabilityEPSS 0.6%CVE-2026-42440HIGHApache OpenNLP: OOM DoS via Unbounded Array Allocation in AbstractModelReaderEPSS 0.6%CVE-2024-48809HIGHAn issue in Open Networking Foundations sdran-in-a-box v.1.4.3 and onos-a1t v.0.2.3 allows a remote attacker to cause a denial of service viEPSS 0.6%CVE-2025-2813HIGHHTTP Service DoS VulnerabilityEPSS 0.6%CVE-2025-10497HIGHAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.6%CVE-2026-55078MEDIUMCoder: Zip upload decompression lacks aggregate size limit, enabling denial of serviceEPSS 0.6%CVE-2024-50311MEDIUMGraphql: denial of service (dos) vulnerability via graphql batchingEPSS 0.6%CVE-2026-26313MEDIUMGo Ethereum affected by DoS via malicious p2p messageEPSS 0.6%CVE-2024-31881MEDIUMIBM Db2 denial of serviceEPSS 0.6%CVE-2023-32481MEDIUM Wyse Management Suite versions prior to 4.0 contain a denial-of-service vulnerability. An authenticated malicious user can flood the configEPSS 0.6%CVE-2025-24317MEDIUMAllocation of resources without limits or throttling issue exists in HMI ViewJet C-more series and HMI GC-A2 series, which may allow a remotEPSS 0.6%CVE-2025-8537MEDIUMAxiomatic Bento4 mp4decrypt Mp4Decrypt.cpp SetDataSize allocation of resourcesEPSS 0.6%CVE-2026-33332MEDIUMNiceGUI's unvalidated chunk size parameter in media routes can cause memory exhaustionEPSS 0.6%CVE-2021-47137CRITICALnet: lantiq: fix memory corruption in RX ringEPSS 0.6%CVE-2024-50285HIGHksmbd: check outstanding simultaneous SMB operationsEPSS 0.6%CVE-2024-37302HIGHSynapse denial of service through media disk space consumptionEPSS 0.6%CVE-2023-49559LOWAn issue in vektah gqlparser open-source-library v.2.5.10 allows a remote attacker to cause a denial of service via a crafted script to the EPSS 0.6%CVE-2025-8014HIGHAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.6%CVE-2026-1102MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.6%