Falhas do tipo CWE-770

1.861 resultados

Alocação de recursos sem limite (negação de serviço por esgotamento)

A aplicação aloca recursos (memória, conexões, arquivos, threads) a pedido de um usuário sem impor limites, permitindo que um atacante esgote todos os recursos disponíveis e derrube o serviço. É basicamente deixar a porta aberta para qualquer um encher a caixa d'água até transbordar.

Exemplo

Um servidor web que cria uma nova thread para cada requisição HTTP recebida, sem limite. Um atacante envia milhares de requisições simultâneas e esgota o pool de threads, tornando o servidor inresponsivo para usuários legítimos — é negação de serviço puro.

Como mitigar

Implemente limites rigorosos: rate limiting (requisições por IP/usuário), quotas de recursos, pool de threads/conexões com tamanho máximo, timeout em operações, e monitoramento de consumo. Valide tamanhos de entrada e rejeite alocações que excedam os limites configurados.

CVE-2026-12707HIGHUnbounded path event queue growth in quiche via peer-driven source connection ID rotationEPSS 0.4%CVE-2026-14362MEDIUMDenial of service via crafted push/pull gossip message in memberlistEPSS 0.4%CVE-2026-56143MEDIUMAllocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of ServiceEPSS 0.4%CVE-2023-25656HIGHnotation-go has excessive memory allocation on verificationEPSS 0.4%CVE-2025-62666MEDIUMDoS vector through the cirrusbuilddoc query APIEPSS 0.4%CVE-2026-22815MEDIUMAIOHTTP: Uncapped memory usage possible through aiohttp allowing unlimited trailer headersEPSS 0.4%CVE-2025-59421LOWPress vulnerable to email flooding to users due to lack of validation and rate limitsEPSS 0.4%CVE-2026-6948MEDIUMUnbounded Memory Allocation in VQLResponse Result-Set WriterEPSS 0.4%CVE-2025-27795MEDIUMReadJXLImage in JXL in GraphicsMagick before 1.3.46 lacks image dimension resource limits.EPSS 0.4%CVE-2024-31617MEDIUMOpenLiteSpeed before 1.8.1 mishandles chunked encoding.EPSS 0.4%CVE-2025-3475MEDIUMWEB-T - Moderately critical - Access bypass, Denial of service - SA-CONTRIB-2025-030EPSS 0.4%CVE-2024-46933HIGHAn issue was discovered in Atos Eviden BullSequana XH2140 BMC before C4EM-125: OMF_C4E 101.05.0014. Some BullSequana XH products were shippeEPSS 0.4%CVE-2023-45028MEDIUMQTS, QuTS hero, QuTScloudEPSS 0.4%CVE-2026-41644HIGHmonetr is vulnerable to server-side request forgery in Lunch Flow link creation and refreshEPSS 0.4%CVE-2026-91970HIGHVikunja before 2.6.0 Resource Exhaustion via Planka MigrationEPSS 0.4%CVE-2026-39904HIGHGophish 0.12.1 Denial of Service via Office Document UploadEPSS 0.4%CVE-2026-85582HIGHSiYuan before v3.8.2 Unbounded Session Creation via Basic AuthEPSS 0.4%CVE-2026-48987MEDIUMpyLoad: Unbounded Memory Growth Leading to DoS and Potential DDoS in EventManagerEPSS 0.4%CVE-2026-61617HIGHPterodactyl Wings SFTP write path does not enforce disk quota, allowing node-wide disk exhaustionEPSS 0.4%CVE-2026-61652HIGHZapros: Streaming decoders ignored the requested chunk size, allowing a single compressed response chunk to allocate unbounded memory (decompression bomb)EPSS 0.4%