Falhas do tipo CWE-770

1.861 resultados

Alocação de recursos sem limite (negação de serviço por esgotamento)

A aplicação aloca recursos (memória, conexões, arquivos, threads) a pedido de um usuário sem impor limites, permitindo que um atacante esgote todos os recursos disponíveis e derrube o serviço. É basicamente deixar a porta aberta para qualquer um encher a caixa d'água até transbordar.

Exemplo

Um servidor web que cria uma nova thread para cada requisição HTTP recebida, sem limite. Um atacante envia milhares de requisições simultâneas e esgota o pool de threads, tornando o servidor inresponsivo para usuários legítimos — é negação de serviço puro.

Como mitigar

Implemente limites rigorosos: rate limiting (requisições por IP/usuário), quotas de recursos, pool de threads/conexões com tamanho máximo, timeout em operações, e monitoramento de consumo. Valide tamanhos de entrada e rejeite alocações que excedam os limites configurados.

CVE-2026-80179MEDIUMJwcrypto: jwcrypto: denial of service via malformed jwe tokensEPSS 0.4%CVE-2020-37039MEDIUMFrigate 2.02 - Denial Of ServiceEPSS 0.4%CVE-2026-58488MEDIUMHedgeDoc: Rate-limit bypass via CF-Connecting-IP header spoofingEPSS 0.4%CVE-2025-1677MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.4%CVE-2026-85219LOWDenial-of-Service in the OpenCanary Redis serviceEPSS 0.4%CVE-2026-46553LOWNocoDB: Attachment Size Limit Bypass via Upload-by-URLEPSS 0.4%CVE-2026-85220LOWDenial-of-Service in the Thinkst Canary Redis serviceEPSS 0.4%CVE-2026-48510MEDIUMMessagePack-CSharp: LZ4 decompression allocates from unbounded declared output lengthsEPSS 0.4%CVE-2026-48514MEDIUMMessagePack-CSharp: Unity unsafe blit formatter allocates from unbounded byte lengthEPSS 0.4%CVE-2025-55102HIGHA denial-of-service vulnerability exists in the NetX IPv6 component functionality of Eclipse ThreadX NetX Duo. A specially crafted network pEPSS 0.4%CVE-2026-48515MEDIUMMessagePack-CSharp: Multi-dimensional array formatters allocate from unchecked dimensionsEPSS 0.4%CVE-2026-40395MEDIUMVarnish Enterprise before 6.0.16r12 allows a "workspace overflow" denial of service (daemon panic) for shared VCL. The headerplus.write_req0EPSS 0.4%CVE-2021-47875MEDIUMGeoGebra CAS Calculator 6.0.631.0 - Denial of ServiceEPSS 0.4%CVE-2024-51461MEDIUMIBM QRadar WinCollect Agent denial of serviceEPSS 0.4%CVE-2026-23826HIGHUnauthenticated Denial of Service in AOS-8 Network Management ServiceEPSS 0.4%CVE-2025-22484HIGHFile Station 5EPSS 0.4%CVE-2025-66473HIGHXWiki's REST APIs don't enforce any limits, leading to unavailability and OOM in large wikisEPSS 0.4%CVE-2025-5253MEDIUMDoS in Kron Technologies' Kron PAMEPSS 0.4%CVE-2026-82054HIGHUncontrolled Resource Consumption in MongoDB Server JSON Pointer Parser Leads to Denial of ServiceEPSS 0.4%CVE-2025-3922MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.4%