Falhas do tipo CWE-770

1.861 resultados

Alocação de recursos sem limite (negação de serviço por esgotamento)

A aplicação aloca recursos (memória, conexões, arquivos, threads) a pedido de um usuário sem impor limites, permitindo que um atacante esgote todos os recursos disponíveis e derrube o serviço. É basicamente deixar a porta aberta para qualquer um encher a caixa d'água até transbordar.

Exemplo

Um servidor web que cria uma nova thread para cada requisição HTTP recebida, sem limite. Um atacante envia milhares de requisições simultâneas e esgota o pool de threads, tornando o servidor inresponsivo para usuários legítimos — é negação de serviço puro.

Como mitigar

Implemente limites rigorosos: rate limiting (requisições por IP/usuário), quotas de recursos, pool de threads/conexões com tamanho máximo, timeout em operações, e monitoramento de consumo. Valide tamanhos de entrada e rejeite alocações que excedam os limites configurados.

CVE-2025-53538HIGHSuricata's mishandling of data on HTTP2 stream 0 can lead to resource starvationEPSS 0.5%CVE-2026-1402MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.5%CVE-2025-32777HIGHVolcano Scheduler Denial of Service via Unbounded Response from Elastic Service/extender PluginEPSS 0.5%CVE-2026-67230MEDIUMRabbitMQ: Web-STOMP unbounded pre-auth accumulationEPSS 0.5%CVE-2026-31935HIGHSuricata http2: unbounded resource consumptionEPSS 0.5%CVE-2025-1059HIGHCWE-770: Allocation of Resources Without Limits or Throttling vulnerability exists that could cause communications to stop when malicious paEPSS 0.5%CVE-2024-37681MEDIUMAn issue the background management system of Shanxi Internet Chuangxiang Technology Co., Ltd v1.0.1 allows a remote attacker to cause a deniEPSS 0.5%CVE-2024-53857HIGHrPGP Potential Resource Exhaustion when handling Untrusted MessagesEPSS 0.5%CVE-2026-62641MEDIUMIn Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of service via a crafted compressed-RTF siEPSS 0.5%CVE-2026-71486MEDIUMvLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output boundsEPSS 0.5%CVE-2026-49140MEDIUMNanobot < 0.2.1 Denial of Service via Matrix Media Download HandlerEPSS 0.5%CVE-2026-82722HIGHAshAdmin LiveView events intern atoms from client input, exhausting the atom table (node DoS)EPSS 0.5%CVE-2025-2853MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.5%CVE-2025-37166HIGHUnexpected shutdown in HPE Instant On Access Points after processing specific packetsEPSS 0.5%CVE-2026-56324HIGHCapgo - Rate Limit Bypass via User-Controlled device_id ParameterEPSS 0.5%CVE-2025-57708LOWQsync CentralEPSS 0.5%CVE-2024-35185MEDIUMDenial of service of Minder Server with attacker-controlled REST endpointEPSS 0.5%CVE-2025-56223HIGHA lack of rate limiting in the component /Home/UploadStreamDocument of SigningHub v8.6.8 allows attackers to cause a Denial of Service (DoS)EPSS 0.5%CVE-2026-22036MEDIUMUndici has an unbounded decompression chain in HTTP responses on Node.js Fetch API via Content-Encoding leads to resource exhaustionEPSS 0.5%CVE-2024-21875MEDIUMDoS attack when broadcasting billboard messagesEPSS 0.5%