Falhas do tipo CWE-770

1.861 resultados

Alocação de recursos sem limite (negação de serviço por esgotamento)

A aplicação aloca recursos (memória, conexões, arquivos, threads) a pedido de um usuário sem impor limites, permitindo que um atacante esgote todos os recursos disponíveis e derrube o serviço. É basicamente deixar a porta aberta para qualquer um encher a caixa d'água até transbordar.

Exemplo

Um servidor web que cria uma nova thread para cada requisição HTTP recebida, sem limite. Um atacante envia milhares de requisições simultâneas e esgota o pool de threads, tornando o servidor inresponsivo para usuários legítimos — é negação de serviço puro.

Como mitigar

Implemente limites rigorosos: rate limiting (requisições por IP/usuário), quotas de recursos, pool de threads/conexões com tamanho máximo, timeout em operações, e monitoramento de consumo. Valide tamanhos de entrada e rejeite alocações que excedam os limites configurados.

CVE-2026-91970HIGHVikunja before 2.6.0 Resource Exhaustion via Planka MigrationEPSS 0.4%CVE-2026-48987MEDIUMpyLoad: Unbounded Memory Growth Leading to DoS and Potential DDoS in EventManagerEPSS 0.4%CVE-2022-48498HIGHConfiguration defects in the secure OS module.Successful exploitation of this vulnerability will affect availability.EPSS 0.4%CVE-2023-34166HIGHVulnerability of system restart triggered by abnormal callbacks passed to APIs.Successful exploitation of this vulnerability may cause the sEPSS 0.4%CVE-2025-23028MEDIUMDoS in Cilium agent DNS proxy from crafted DNS responsesEPSS 0.4%CVE-2025-69233MEDIUMApache CloudStack: Domain/account resources limits not honoredEPSS 0.4%CVE-2026-57212HIGHRabbitMQ management HTTP API accepts request bodies larger than configured max_http_body_sizeEPSS 0.4%CVE-2025-46807HIGHFile Descriptor Exhaustion in sslh-select and sslh-ev triggers SEGFAULTEPSS 0.4%CVE-2026-41484MEDIUMOpenTelemetry.Exporter.OneCollector vulnerable to denial of service via unbounded HTTP error response bodyEPSS 0.4%CVE-2026-42127HIGHPre-authentication denial of service in the public dashboard query endpointEPSS 0.4%CVE-2026-78662HIGHPrevent DoS on deadlocked undecided channel in golang.org/x/crypto/sshEPSS 0.4%CVE-2022-20494MEDIUMIn AutomaticZenRule of AutomaticZenRule.java, there is a possible persistent DoS due to resource exhaustion. This could lead to local denialEPSS 0.4%CVE-2025-30350MEDIUMDirectus's S3 assets become unavailable after a burst of HEAD requestsEPSS 0.4%CVE-2025-48040MEDIUMMalicious Key Exchange Messages may Lead to Excessive Resource ConsumptionEPSS 0.4%CVE-2025-36319MEDIUMVulnerabilities found in Watson Data IntelligenceEPSS 0.4%CVE-2025-30225MEDIUMDirectus's S3 assets become unavailable after a burst of malformed transformationsEPSS 0.4%CVE-2026-79661MEDIUMEch0 before 4.7.3 Unauthenticated fav_count ModificationEPSS 0.4%CVE-2026-58238MEDIUMMultiple vulnerabilities in SAP Business AI Platform (Approuter)EPSS 0.4%CVE-2026-21434MEDIUMwebtransport-go affected by Memory Exhaustion Attack due to Missing Length Check in WT_CLOSE_SESSION CapsuleEPSS 0.4%CVE-2025-46706HIGHBIG-IP iRules vulnerabilityEPSS 0.4%