Falhas do tipo CWE-770

1.861 resultados

Alocação de recursos sem limite (negação de serviço por esgotamento)

A aplicação aloca recursos (memória, conexões, arquivos, threads) a pedido de um usuário sem impor limites, permitindo que um atacante esgote todos os recursos disponíveis e derrube o serviço. É basicamente deixar a porta aberta para qualquer um encher a caixa d'água até transbordar.

Exemplo

Um servidor web que cria uma nova thread para cada requisição HTTP recebida, sem limite. Um atacante envia milhares de requisições simultâneas e esgota o pool de threads, tornando o servidor inresponsivo para usuários legítimos — é negação de serviço puro.

Como mitigar

Implemente limites rigorosos: rate limiting (requisições por IP/usuário), quotas de recursos, pool de threads/conexões com tamanho máximo, timeout em operações, e monitoramento de consumo. Valide tamanhos de entrada e rejeite alocações que excedam os limites configurados.

CVE-2025-32386MEDIUMHelm Allows A Specially Crafted Chart Archive To Cause Out Of Memory TerminationEPSS 0.4%CVE-2026-22773MEDIUMvLLM is vulnerable to DoS in Idefics3 vision models via image payload with ambiguous dimensionsEPSS 0.4%CVE-2023-4138MEDIUMAllocation of Resources Without Limits or Throttling in ikus060/rdiffwebEPSS 0.4%CVE-2026-28452MEDIUMOpenClaw < 2026.2.14 - Denial of Service via Unguarded Archive Extraction in extractArchiveEPSS 0.4%CVE-2026-44679MEDIUMTuist: Forgot password flow lacks throttling for reset email deliveryEPSS 0.4%CVE-2026-8488MEDIUMAllocation of resources without limits or throttling vulnerability in Progress Software MOVEit AutomationEPSS 0.4%CVE-2026-74784HIGHScriban before 7.2.0 Denial of Service via array.insert_atEPSS 0.4%CVE-2026-24006HIGHSeroval affected by Denial of Service via Deeply Nested ObjectsEPSS 0.4%CVE-2026-54464MEDIUMwebsocket-driver: Resource limit bypass via message compressionEPSS 0.4%CVE-2026-23957HIGHseroval is vulnerable to Denial of Service via array serializationEPSS 0.4%CVE-2026-54490MEDIUMwebsocket-driver: Resource limit bypass via message compressionEPSS 0.4%CVE-2026-32941MEDIUMSliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard TransportsEPSS 0.4%CVE-2026-33743MEDIUMIncus vulnerable to denial of source through crafted bucket backup fileEPSS 0.4%CVE-2026-54024MEDIUMLibreChat: Incomplete Fix for CVE-2024-11171 — Conversation Import Multer Instance Missing File Size LimitsEPSS 0.4%CVE-2026-33541MEDIUMTSPortal's Uncontrolled User Creation via Validation Side Effects Leads to Potential Denial of ServiceEPSS 0.4%CVE-2026-33438MEDIUMStirling-PDF vulnerable to DoS via add-watermarkEPSS 0.4%CVE-2026-13074MEDIUMAwaitable Hello Command in Exhaust Mode Unthrottled Response Loop Leading to Denial of ServiceEPSS 0.4%CVE-2026-54448MEDIUMTrivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parserEPSS 0.4%CVE-2026-33621MEDIUMPinchTab: Unapplied Rate Limiting Middleware Allows Unbounded Brute-Force of API TokenEPSS 0.4%CVE-2025-3221HIGHIBM InfoSphere Information Server denial of serviceEPSS 0.4%