Falhas do tipo CWE-770

1.846 resultados

Alocação de recursos sem limite (negação de serviço por esgotamento)

A aplicação aloca recursos (memória, conexões, arquivos, threads) a pedido de um usuário sem impor limites, permitindo que um atacante esgote todos os recursos disponíveis e derrube o serviço. É basicamente deixar a porta aberta para qualquer um encher a caixa d'água até transbordar.

Exemplo

Um servidor web que cria uma nova thread para cada requisição HTTP recebida, sem limite. Um atacante envia milhares de requisições simultâneas e esgota o pool de threads, tornando o servidor inresponsivo para usuários legítimos — é negação de serviço puro.

Como mitigar

Implemente limites rigorosos: rate limiting (requisições por IP/usuário), quotas de recursos, pool de threads/conexões com tamanho máximo, timeout em operações, e monitoramento de consumo. Valide tamanhos de entrada e rejeite alocações que excedam os limites configurados.

CVE-2023-51334MEDIUMA lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Cinema Booking System v1.0 allows attackers to send an excessive amouEPSS 0.6%CVE-2024-46667MEDIUMA allocation of resources without limits or throttling in Fortinet FortiSIEM 5.3 all versions, 5.4 all versions, 6.x all versions, 7.0 all vEPSS 0.6%CVE-2026-91080HIGHwebhook through 2.8.3 Memory Exhaustion via Oversized Request BodyEPSS 0.6%CVE-2024-45662HIGHIBM Safer Payments denial of serviceEPSS 0.6%CVE-2023-37934MEDIUMAn allocation of resources without limits or throttling vulnerability [CWE-770] in FortiPAM 1.0 all versions allows an authenticated attackeEPSS 0.6%CVE-2023-32699MEDIUMMeterSphere denial of service vulnerabilityEPSS 0.6%CVE-2026-18618HIGHMl-metdata: bundled grpc 1.46.3 (2022) with published http/2 dos cves — directly reachable on listenerEPSS 0.6%CVE-2024-28870HIGHSuricata uses excessive resource use in malformed ssh traffic parsingEPSS 0.6%CVE-2026-49955MEDIUMHermes WebUI < 0.51.270 Resource Exhaustion via passkey/optionsEPSS 0.6%CVE-2026-24133HIGHjsPDF Affected by Denial of Service (DoS) via Unvalidated BMP Dimensions in BMPDecoderEPSS 0.6%CVE-2024-48530HIGHAn issue in the Instructor Appointment Availability module of eSoft Planner 3.24.08271-USA allows attackers to cause a Denial of Service (DoEPSS 0.6%CVE-2026-40006HIGHApache IoTDB: Unauthenticated heap-exhaustion DoS via unbounded allocation in IoTDB AirGap pipe receiverEPSS 0.6%CVE-2024-44241CRITICALThe issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1. An attacker may beEPSS 0.6%CVE-2026-33258MEDIUMCrafted zones can cause increased resource usageEPSS 0.6%CVE-2026-49361HIGHApache Fluss Netty Frame Decoder Memory Exhaustion VulnerabilityEPSS 0.6%CVE-2025-32031HIGHApollo Gateway Query Planner Vulnerable to Excessive Resource Consumption via Optimization BypassEPSS 0.6%CVE-2025-10858HIGHAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.6%CVE-2025-53069MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services). Supported versions that are affected arEPSS 0.6%CVE-2024-8391MEDIUMEclipse Vert.x gRPC server does not limit the maximum message sizeEPSS 0.6%CVE-2023-4912LOWAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.6%