Falhas do tipo CWE-770

1.861 resultados

Alocação de recursos sem limite (negação de serviço por esgotamento)

A aplicação aloca recursos (memória, conexões, arquivos, threads) a pedido de um usuário sem impor limites, permitindo que um atacante esgote todos os recursos disponíveis e derrube o serviço. É basicamente deixar a porta aberta para qualquer um encher a caixa d'água até transbordar.

Exemplo

Um servidor web que cria uma nova thread para cada requisição HTTP recebida, sem limite. Um atacante envia milhares de requisições simultâneas e esgota o pool de threads, tornando o servidor inresponsivo para usuários legítimos — é negação de serviço puro.

Como mitigar

Implemente limites rigorosos: rate limiting (requisições por IP/usuário), quotas de recursos, pool de threads/conexões com tamanho máximo, timeout em operações, e monitoramento de consumo. Valide tamanhos de entrada e rejeite alocações que excedam os limites configurados.

CVE-2025-1516MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.4%CVE-2025-7449MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.4%CVE-2021-33011—All versions of the afffected TOYOPUC-PC10 Series,TOYOPUC-Plus Series,TOYOPUC-PC3J/PC2J Series, TOYOPUC-Nano Series products may not be ableEPSS 0.4%CVE-2026-34052MEDIUMLTI JupyterHub Authenticator: Unbounded Memory Growth via Nonce Storage (Denial of Service)EPSS 0.4%CVE-2026-73198HIGHIpa: freeipa: unauthenticated dos in `/ipa/i18n_messages` via unbounded request body readEPSS 0.4%CVE-2025-68388MEDIUMAllocation of resources without limits or throttling (CWE-770) allows an unauthenticated remote attacker to cause excessive allocation (CAPEEPSS 0.4%CVE-2026-84890MEDIUMundici vulnerable to Denial of Service via unbounded decompression of compressed responsesEPSS 0.4%CVE-2025-13165HIGHDigiwin|EasyFlow GP - Denial of serviceEPSS 0.4%CVE-2026-12590LOWbody-parser vulnerable to denial of service when invalid limit value silently disables size enforcementEPSS 0.4%CVE-2026-73197HIGHIpa: freeipa: unauthenticated dos in `/ipa/migration/migration.py` via unbounded request body readEPSS 0.4%CVE-2025-58058MEDIUMgithub.com/ulikunitz/xz leaks memory when decoding a corrupted multiple LZMA archivesEPSS 0.4%CVE-2026-46551MEDIUMNocoDB: Missing File Size Enforcement in Upload-by-URL Allows Denial of Service via Disk ExhaustionEPSS 0.4%CVE-2026-53522MEDIUMNezha Monitoring: Unbounded WebSocket Streams — Resource Exhaustion DoSEPSS 0.4%CVE-2026-36499MEDIUMA missing upper-bound check in the udpif_set_threads() function of Open vSwitch v3.6.90 allows an attacker with OVSDB write access to requesEPSS 0.4%CVE-2026-47013MEDIUMVulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u491. Easily exploitable vEPSS 0.4%CVE-2025-65015CRITICALjoserfc has Possible Uncontrolled Resource Consumption Vulnerability Triggered by Logging Arbitrarily Large JWT Token PayloadsEPSS 0.4%CVE-2026-40115MEDIUMPraisonAI has an Unrestricted Upload Size in WSGI Recipe Registry Server Enables Memory Exhaustion DoSEPSS 0.4%CVE-2026-58107MEDIUMAuthenticated Remote Denial of Service via Unbounded zlib Decompression in massStoreRunEPSS 0.4%CVE-2026-92063MEDIUMDenial-of-service in the Audio/Video componentEPSS 0.4%CVE-2026-57224MEDIUMSuricata dhcp: unbounded transactions in unidirectional traffic can lead to resource exhaustionEPSS 0.4%