Falhas do tipo CWE-770

1.861 resultados

Alocação de recursos sem limite (negação de serviço por esgotamento)

A aplicação aloca recursos (memória, conexões, arquivos, threads) a pedido de um usuário sem impor limites, permitindo que um atacante esgote todos os recursos disponíveis e derrube o serviço. É basicamente deixar a porta aberta para qualquer um encher a caixa d'água até transbordar.

Exemplo

Um servidor web que cria uma nova thread para cada requisição HTTP recebida, sem limite. Um atacante envia milhares de requisições simultâneas e esgota o pool de threads, tornando o servidor inresponsivo para usuários legítimos — é negação de serviço puro.

Como mitigar

Implemente limites rigorosos: rate limiting (requisições por IP/usuário), quotas de recursos, pool de threads/conexões com tamanho máximo, timeout em operações, e monitoramento de consumo. Valide tamanhos de entrada e rejeite alocações que excedam os limites configurados.

CVE-2026-54716HIGHValhalla: Degenerate exclude_polygons (collinear points, zero area) causes OOM in /sources_to_targetsEPSS 0.5%CVE-2026-30071HIGHAn issue in the RechargePut function of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.EPSS 0.5%CVE-2026-45290HIGHCloudburst Network has DoS in RakNet connection handling due to missing bound checksEPSS 0.5%CVE-2026-30051HIGHAn issue in the CreateUEContextProcedure function (/v1/ue-contexts/{supi}) of free5gc v4.1.0 allows attackers to cause a Denial of Service (EPSS 0.5%CVE-2026-30067HIGHAn issue in the complexQueryFilterSubprocess function in the NRF Discovery service of free5gc v4.0.1 allows attackers to cause a Denial of SEPSS 0.5%CVE-2026-41851MEDIUMSpring Framework Denial of Service via Unbounded Cache in SpELEPSS 0.5%CVE-2026-41007HIGHSpring HATEOAS heap exhaustion through unbounded internal cachingEPSS 0.5%CVE-2026-48702HIGHRekor has an OOM Condition due to Unbounded gzip Decompression in Alpine APK Parsing LogicEPSS 0.5%CVE-2026-21729HIGHLoki detected_fields query limits results in unbounded memory allocationEPSS 0.5%CVE-2026-34826MEDIUMRack: Unbounded Range Count in get_byte_ranges Enables DoSEPSS 0.5%CVE-2026-30060HIGHAn issue in free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) when parsing crafted SUCI data during UE registration.EPSS 0.5%CVE-2025-68148MEDIUMFreshRSS globally denies access to feed via proxy modifying to 429 Retry-AfterEPSS 0.5%CVE-2026-40629HIGHBIG-IP SSL/TLS vulnerabilityEPSS 0.5%CVE-2026-30050HIGHAn issue in the ModifyAMFEventSubscriptionProcedure function (processor/event_exposure.go) of free5gc v4.1.0 allows attackers to cause a DenEPSS 0.5%CVE-2026-44697HIGHKlever-Go MultiDataInterceptor: remote OOM via crafted compressed P2P payloadEPSS 0.5%CVE-2026-81285HIGHWordPress Smush Image Compression and Optimization plugin <= 4.2.0 - Denial of Service Attack vulnerabilityEPSS 0.5%CVE-2026-46702HIGHRussh: Post-decompression SSH packet size was not bounded, allowing remote oversized compressed packetsEPSS 0.5%CVE-2026-30059HIGHAn issue in the NAS decoder component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted Registration RequeEPSS 0.5%CVE-2025-53628MEDIUMcpp-httplib does not limit the length of a lineEPSS 0.5%CVE-2025-30260HIGHQsync CentralEPSS 0.5%