Falhas do tipo CWE-770

1.861 resultados

Alocação de recursos sem limite (negação de serviço por esgotamento)

A aplicação aloca recursos (memória, conexões, arquivos, threads) a pedido de um usuário sem impor limites, permitindo que um atacante esgote todos os recursos disponíveis e derrube o serviço. É basicamente deixar a porta aberta para qualquer um encher a caixa d'água até transbordar.

Exemplo

Um servidor web que cria uma nova thread para cada requisição HTTP recebida, sem limite. Um atacante envia milhares de requisições simultâneas e esgota o pool de threads, tornando o servidor inresponsivo para usuários legítimos — é negação de serviço puro.

Como mitigar

Implemente limites rigorosos: rate limiting (requisições por IP/usuário), quotas de recursos, pool de threads/conexões com tamanho máximo, timeout em operações, e monitoramento de consumo. Valide tamanhos de entrada e rejeite alocações que excedam os limites configurados.

CVE-2026-71408MEDIUMA allocation of resources without limits or throttling vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortEPSS 0.4%CVE-2026-82054HIGHUncontrolled Resource Consumption in MongoDB Server JSON Pointer Parser Leads to Denial of ServiceEPSS 0.4%CVE-2026-47874MEDIUMReactor Netty HTTP Server Denial of Service With Pipelined RequestsEPSS 0.4%CVE-2026-84775MEDIUMWordPress Really Simple SSL plugin <= 9.8.0 - Denial of Service Attack vulnerabilityEPSS 0.4%CVE-2025-43211MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS SeEPSS 0.4%CVE-2026-19015MEDIUMUncontrolled resource consumption in the Consul Connect CA roots endpointEPSS 0.4%CVE-2026-59323MEDIUMMicrometer Tracing Brave Bridge W3C Baggage propagation DoS vulnerabilityEPSS 0.4%CVE-2026-53596MEDIUMFreeScout has unrestricted file upload without rate limiting that leads to resource exhaustion (DoS)EPSS 0.4%CVE-2025-0186MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.4%CVE-2026-84780MEDIUMWordPress WP Go Maps plugin <= 10.1.08 - Denial of Service Attack vulnerabilityEPSS 0.4%CVE-2026-1660MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.4%CVE-2025-3922MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.4%CVE-2025-24312HIGHBIG-IP AFM vulnerabilityEPSS 0.4%CVE-2026-27695MEDIUMzae-limiter: DynamoDB hot partition throttling enables per-entity Denial of ServiceEPSS 0.4%CVE-2026-41310MEDIUMOpenTelemetry .NET Zipkin exporter has unbounded remote endpoint cache leading to memory growthEPSS 0.4%CVE-2024-6098MEDIUMPTC Kepware ThingWorx Kepware Server Allocation of Resources Without Limits or ThrottlingEPSS 0.4%CVE-2025-27144MEDIUMGo JOSE's Parsing Vulnerable to Denial of ServiceEPSS 0.4%CVE-2025-4416HIGHEvents Log Track - Moderately critical - Denial of Service - SA-CONTRIB-2025-059EPSS 0.4%CVE-2025-65113MEDIUMClipBucket v5 Unauthenticated Object Flagging VulnerabilityEPSS 0.4%CVE-2025-36070MEDIUMIBM Db2 Denial of ServiceEPSS 0.4%