Falhas do tipo CWE-770

1.861 resultados

Alocação de recursos sem limite (negação de serviço por esgotamento)

A aplicação aloca recursos (memória, conexões, arquivos, threads) a pedido de um usuário sem impor limites, permitindo que um atacante esgote todos os recursos disponíveis e derrube o serviço. É basicamente deixar a porta aberta para qualquer um encher a caixa d'água até transbordar.

Exemplo

Um servidor web que cria uma nova thread para cada requisição HTTP recebida, sem limite. Um atacante envia milhares de requisições simultâneas e esgota o pool de threads, tornando o servidor inresponsivo para usuários legítimos — é negação de serviço puro.

Como mitigar

Implemente limites rigorosos: rate limiting (requisições por IP/usuário), quotas de recursos, pool de threads/conexões com tamanho máximo, timeout em operações, e monitoramento de consumo. Valide tamanhos de entrada e rejeite alocações que excedam os limites configurados.

CVE-2026-40881MEDIUMZebra: addr/addrv2 Deserialization Resource ExhaustionEPSS 0.5%CVE-2026-30070HIGHAn issue in the HandleGetSharedData function of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.EPSS 0.5%CVE-2026-30062HIGHAn issue in the NGAP handler of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted NAS PDU.EPSS 0.5%CVE-2024-47401MEDIUMDoS via Amplified GraphQL Response in PlaybooksEPSS 0.5%CVE-2025-29890HIGHFile Station 5EPSS 0.5%CVE-2026-48888HIGHWordPress WooCommerce plugin < 11.1.0 - Denial of Service Attack vulnerabilityEPSS 0.5%CVE-2026-30059HIGHAn issue in the NAS decoder component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted Registration RequeEPSS 0.5%CVE-2026-41716HIGHSpring Data web support unbounded negative-result cache keyed on attacker-supplied property namesEPSS 0.5%CVE-2026-54609HIGHQTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwardingEPSS 0.5%CVE-2026-46673HIGHRussh: Unchecked CryptoVec allocation and growth handling is reachable from local agent inputs in current russh releases and from remote SSH traffic in historical pre-0.58.0 releasesEPSS 0.5%CVE-2026-30063HIGHAn issue in the NF Discovery endpoint of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted snssais query.EPSS 0.5%CVE-2026-84778HIGHWordPress Migrate Guru – Site Migration & Cloning plugin <= 6.65 - Denial of Service Attack vulnerabilityEPSS 0.5%CVE-2025-29900HIGHFile Station 5EPSS 0.5%CVE-2026-84776HIGHWordPress MalCare Security plugin <= 6.69 - Denial of Service Attack vulnerabilityEPSS 0.5%CVE-2026-34826MEDIUMRack: Unbounded Range Count in get_byte_ranges Enables DoSEPSS 0.5%CVE-2025-55197MEDIUMpypdf's Manipulated FlateDecode streams can exhaust RAMEPSS 0.5%CVE-2025-62706MEDIUMAuthlib : JWE zip=DEF decompression bomb enables DoSEPSS 0.5%CVE-2024-28760MEDIUMIBM App Connect Enterprise denial of serviceEPSS 0.5%CVE-2024-1666HIGHUnauthorized Radar Creation in lunary-ai/lunaryEPSS 0.5%CVE-2024-3760HIGHEmail Bombing Vulnerability in lunary-ai/lunaryEPSS 0.5%