Falhas do tipo CWE-770

1.861 resultados

Alocação de recursos sem limite (negação de serviço por esgotamento)

A aplicação aloca recursos (memória, conexões, arquivos, threads) a pedido de um usuário sem impor limites, permitindo que um atacante esgote todos os recursos disponíveis e derrube o serviço. É basicamente deixar a porta aberta para qualquer um encher a caixa d'água até transbordar.

Exemplo

Um servidor web que cria uma nova thread para cada requisição HTTP recebida, sem limite. Um atacante envia milhares de requisições simultâneas e esgota o pool de threads, tornando o servidor inresponsivo para usuários legítimos — é negação de serviço puro.

Como mitigar

Implemente limites rigorosos: rate limiting (requisições por IP/usuário), quotas de recursos, pool de threads/conexões com tamanho máximo, timeout em operações, e monitoramento de consumo. Valide tamanhos de entrada e rejeite alocações que excedam os limites configurados.

CVE-2024-57722HIGHlunasvg v3.0.0 was discovered to contain a allocation-size-too-big bug via the component plutovg_surface_create.EPSS 0.5%CVE-2025-71401CRITICALbetter-auth before 1.4.2 basePath Modification DoSEPSS 0.5%CVE-2025-1250MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.5%CVE-2025-7337MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.5%CVE-2025-26480MEDIUMDell PowerScale OneFS, versions 9.5.0.0 through 9.10.0.0, contains an uncontrolled resource consumption vulnerability. An unauthenticated atEPSS 0.5%CVE-2026-34077HIGHReact Router vulnerable to Denial of Service via reflected user input in single-fetchEPSS 0.5%CVE-2025-1257MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.5%CVE-2014-125127HIGHDenial of Service (DoS) vulnerability in mikecao/flightEPSS 0.5%CVE-2025-0639MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.5%CVE-2026-55531MEDIUMPraisonAI: Unauthenticated unbounded session accumulation in the PraisonAI MCP HTTP server (memory exhaustion; session TTL never enforced)EPSS 0.5%CVE-2026-8202MEDIUMPost-authentication CPU utilization DoS via $trim/$ltrim/$rtrim operatorsEPSS 0.5%CVE-2026-48854HIGHUnbounded request body accumulation causes memory exhaustion in elixir-grpc/grpcEPSS 0.5%CVE-2025-36047MEDIUMIBM WebSphere Application Server Liberty denial of serviceEPSS 0.5%CVE-2026-45802MEDIUMFPDI: Memory Exhaustion and Endless Loop in FPDI leads to Denial of ServiceEPSS 0.5%CVE-2026-65650MEDIUMElgg before 7.0.0 does not check image dimensions to prevent denial of service via a large avatar upload.EPSS 0.5%CVE-2021-47959HIGHWordPress Plugin WPGraphQL 1.3.5 Denial of ServiceEPSS 0.5%CVE-2025-59139MEDIUMHono has Body Limit Middleware BypassEPSS 0.4%CVE-2026-62210MEDIUMOpenClaw < 2026.6.1 Denial of Service via Remote Media URLsEPSS 0.4%CVE-2024-23826MEDIUMUploading an image with a specific filename causes a server-side DoS EPSS 0.4%CVE-2026-22773MEDIUMvLLM is vulnerable to DoS in Idefics3 vision models via image payload with ambiguous dimensionsEPSS 0.4%