Falhas do tipo CWE-770

1.861 resultados

Alocação de recursos sem limite (negação de serviço por esgotamento)

A aplicação aloca recursos (memória, conexões, arquivos, threads) a pedido de um usuário sem impor limites, permitindo que um atacante esgote todos os recursos disponíveis e derrube o serviço. É basicamente deixar a porta aberta para qualquer um encher a caixa d'água até transbordar.

Exemplo

Um servidor web que cria uma nova thread para cada requisição HTTP recebida, sem limite. Um atacante envia milhares de requisições simultâneas e esgota o pool de threads, tornando o servidor inresponsivo para usuários legítimos — é negação de serviço puro.

Como mitigar

Implemente limites rigorosos: rate limiting (requisições por IP/usuário), quotas de recursos, pool de threads/conexões com tamanho máximo, timeout em operações, e monitoramento de consumo. Valide tamanhos de entrada e rejeite alocações que excedam os limites configurados.

CVE-2026-61541MEDIUMZapros has an Unbounded Content-Encoding decompression chain that allows denial of serviceEPSS 0.4%CVE-2025-53531HIGHWeGIA allows Uncontrolled Resource Consumption via the fid parameterEPSS 0.4%CVE-2026-75956HIGHJoomla Extension - cmsjunkie.com - DOS vector in pagination parameter handling in J-BusinessDirectory < 6.2.3EPSS 0.4%CVE-2025-53530HIGHWeGIA allows Uncontrolled Resource Consumption via the errorstr parameterEPSS 0.4%CVE-2025-27911MEDIUMAn issue was discovered in Datalust Seq before 2024.3.13545. Expansion of identifiers in message templates can be used to bypass the system EPSS 0.4%CVE-2026-29772MEDIUMAstro: Memory exhaustion DoS due to missing request body size limit in Server IslandsEPSS 0.4%CVE-2026-64773HIGHAn attacker that can reach a container's published TCP port may be able to force the host's forwarding process to buffer an unbounded amountEPSS 0.4%CVE-2026-100656HIGHNetty HttpServerCodec Unbounded Queue Growth via HTTP/1.1 PipeliningEPSS 0.4%CVE-2026-12818CRITICALDVP-12SE Exposure of Sensitive Information VulnerabilityEPSS 0.4%CVE-2026-9140HIGH1718-AENTR/1719-AENTR - Denial of ServiceEPSS 0.4%CVE-2025-54155LOWFile Station 5EPSS 0.4%CVE-2026-73196MEDIUMIpa: freeipa: authenticated dos in `otptoken-add` via unbounded otp key decoding/re-encodingEPSS 0.4%CVE-2025-11362HIGHVersions of the package pdfmake from 0.3.0-beta.1 and before 0.3.0-beta.17 are vulnerable to Allocation of Resources Without Limits or ThrotEPSS 0.4%CVE-2026-77801MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.4%CVE-2026-13260HIGHSecurity vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify AccessEPSS 0.4%CVE-2025-54161LOWFile Station 5EPSS 0.4%CVE-2024-22436MEDIUMA security vulnerability in HPE IceWall Agent products could be exploited remotely to cause a denial of service.EPSS 0.4%CVE-2026-35457HIGHlibp2p-rust has unbounded rendezvous DISCOVER cookies enable remote memory exhaustionEPSS 0.4%CVE-2026-59647MEDIUMCRMF/CMP password-MAC honours unbounded iteration countEPSS 0.4%CVE-2026-58063MEDIUMBCFKS keystore load honours unbounded KDF cost from untrusted fileEPSS 0.4%