Falhas do tipo CWE-770

1.861 resultados

Alocação de recursos sem limite (negação de serviço por esgotamento)

A aplicação aloca recursos (memória, conexões, arquivos, threads) a pedido de um usuário sem impor limites, permitindo que um atacante esgote todos os recursos disponíveis e derrube o serviço. É basicamente deixar a porta aberta para qualquer um encher a caixa d'água até transbordar.

Exemplo

Um servidor web que cria uma nova thread para cada requisição HTTP recebida, sem limite. Um atacante envia milhares de requisições simultâneas e esgota o pool de threads, tornando o servidor inresponsivo para usuários legítimos — é negação de serviço puro.

Como mitigar

Implemente limites rigorosos: rate limiting (requisições por IP/usuário), quotas de recursos, pool de threads/conexões com tamanho máximo, timeout em operações, e monitoramento de consumo. Valide tamanhos de entrada e rejeite alocações que excedam os limites configurados.

CVE-2026-88878MEDIUMTraefik v2.8.2 through v3.6 HTTP/3 Timeout BypassEPSS 0.4%CVE-2025-29872HIGHFile Station 5EPSS 0.4%CVE-2026-59647MEDIUMCRMF/CMP password-MAC honours unbounded iteration countEPSS 0.4%CVE-2026-58063MEDIUMBCFKS keystore load honours unbounded KDF cost from untrusted fileEPSS 0.4%CVE-2025-31496HIGHapollo-compiler Named Fragment Processing VulnerabilityEPSS 0.4%CVE-2025-68156HIGHExpr has Denial of Service via Unbounded Recursion in Builtin FunctionsEPSS 0.4%CVE-2026-61629HIGHnginx ignition has ParseAcceptLanguage `_` separator bypass that enables ~75x CPU amplification via Accept-Language header in i18nMiddlewareEPSS 0.4%CVE-2026-42397MEDIUMAllocation of Resources Without Limits or Throttling in Kibana Leading to Denial of ServiceEPSS 0.4%CVE-2024-54178MEDIUMMultiple vulnerabilities affect IBM Db2® on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data.EPSS 0.4%CVE-2026-33465MEDIUMAllocation of Resources Without Limits or Throttling in Kibana Leading to Denial of ServiceEPSS 0.4%CVE-2026-41726MEDIUMIn Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector headerEPSS 0.4%CVE-2026-72659MEDIUMAllocation of Resources Without Limits or Throttling in Kibana Leading to Denial of ServiceEPSS 0.4%CVE-2026-72667MEDIUMAllocation of Resources Without Limits or Throttling in Kibana Leading to Denial of ServiceEPSS 0.4%CVE-2026-35441MEDIUMDirectus Affected by GraphQL Alias Amplification Denial-of-Service Due to Missing Query Cost/Complexity LimitsEPSS 0.4%CVE-2026-72684MEDIUMAllocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of ServiceEPSS 0.4%CVE-2026-72651MEDIUMAllocation of Resources Without Limits or Throttling in Kibana Leading to Denial of ServiceEPSS 0.4%CVE-2026-72652MEDIUMAllocation of Resources Without Limits or Throttling in Kibana Leading to Denial of ServiceEPSS 0.4%CVE-2026-13075HIGH$rankFusion and $scoreFusion Unbounded Memory Allocation During Error Suggestion GenerationEPSS 0.4%CVE-2026-28376MEDIUMGrafana Live push endpoint allows unbounded memory allocation leading to OOMEPSS 0.4%CVE-2026-78588MEDIUMAllocation of Resources Without Limits or Throttling in Filebeat Leading to Denial of ServiceEPSS 0.4%