Falhas do tipo CWE-770

1.861 resultados

Alocação de recursos sem limite (negação de serviço por esgotamento)

A aplicação aloca recursos (memória, conexões, arquivos, threads) a pedido de um usuário sem impor limites, permitindo que um atacante esgote todos os recursos disponíveis e derrube o serviço. É basicamente deixar a porta aberta para qualquer um encher a caixa d'água até transbordar.

Exemplo

Um servidor web que cria uma nova thread para cada requisição HTTP recebida, sem limite. Um atacante envia milhares de requisições simultâneas e esgota o pool de threads, tornando o servidor inresponsivo para usuários legítimos — é negação de serviço puro.

Como mitigar

Implemente limites rigorosos: rate limiting (requisições por IP/usuário), quotas de recursos, pool de threads/conexões com tamanho máximo, timeout em operações, e monitoramento de consumo. Valide tamanhos de entrada e rejeite alocações que excedam os limites configurados.

CVE-2026-72674MEDIUMAllocation of Resources Without Limits or Throttling in Kibana Leading to Denial of ServiceEPSS 0.4%CVE-2026-28383MEDIUMGrafana plugin resources can lead to unbounded memory allocationEPSS 0.4%CVE-2026-13076HIGHAggregation Framework Memory Exhaustion Leading to Process TerminationEPSS 0.4%CVE-2026-72653MEDIUMAllocation of Resources Without Limits or Throttling in Kibana Leading to Denial of ServiceEPSS 0.4%CVE-2026-72682MEDIUMAllocation of Resources Without Limits or Throttling in Kibana Leading to Denial of ServiceEPSS 0.4%CVE-2020-37038MEDIUMCode Blocks 20.03 - Denial Of ServiceEPSS 0.4%CVE-2026-92915MEDIUMWWBN AVideo userVerifyEmail.php Unauthenticated Access ControlEPSS 0.4%CVE-2025-36504HIGHBIG-IP HTTP/2 vulnerabilityEPSS 0.4%CVE-2025-32393HIGHAutoGPT has a DoS vulnerability in ReadRSSFeedBlockEPSS 0.4%CVE-2026-67353MEDIUMguzzlehttp/guzzle before 7.15.1 Unbounded Cookie Denial of ServiceEPSS 0.4%CVE-2026-48504MEDIUMOpenTelemetry Rust: Unbounded memory allocation in W3C Baggage propagationEPSS 0.4%CVE-2026-10832MEDIUMOrg.wildfly.security/wildfly-elytron-asn1: unbounded memory allocation in wildfly elytron asn.1 derdecoder via crafted der payloadEPSS 0.4%CVE-2025-13436MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.4%CVE-2025-70069HIGHAn issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXConverter.cpp and ConvertMeshMultiMaterial() metEPSS 0.4%CVE-2025-8099HIGHAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.4%CVE-2019-25342HIGHCentova Cast 3.2.12 - Denial of ServiceEPSS 0.4%CVE-2022-50799HIGHFetch Softworks Fetch FTP Client 5.8.2 Remote CPU Consumption Denial of ServiceEPSS 0.4%CVE-2026-44500MEDIUMZEBRA: Allocation Amplification in Inbound Network DeserializersEPSS 0.4%CVE-2025-52867MEDIUMQsync CentralEPSS 0.4%CVE-2025-1478MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.4%