Falhas do tipo CWE-770

1.863 resultados

Alocação de recursos sem limite (negação de serviço por esgotamento)

A aplicação aloca recursos (memória, conexões, arquivos, threads) a pedido de um usuário sem impor limites, permitindo que um atacante esgote todos os recursos disponíveis e derrube o serviço. É basicamente deixar a porta aberta para qualquer um encher a caixa d'água até transbordar.

Exemplo

Um servidor web que cria uma nova thread para cada requisição HTTP recebida, sem limite. Um atacante envia milhares de requisições simultâneas e esgota o pool de threads, tornando o servidor inresponsivo para usuários legítimos — é negação de serviço puro.

Como mitigar

Implemente limites rigorosos: rate limiting (requisições por IP/usuário), quotas de recursos, pool de threads/conexões com tamanho máximo, timeout em operações, e monitoramento de consumo. Valide tamanhos de entrada e rejeite alocações que excedam os limites configurados.

CVE-2025-36070MEDIUMIBM Db2 Denial of ServiceEPSS 0.4%CVE-2026-49347MEDIUMQuest Bot: Ticket creation has no per-user open-ticket limit or cooldownEPSS 0.4%CVE-2026-27887MEDIUMSpin has memory leaks in various WIT interfacesEPSS 0.4%CVE-2026-49249HIGHBoruta: Authenticated atom-exhaustion DoS in BorutaIdentityWeb.UserSettingsController.update/2EPSS 0.4%CVE-2026-5762MEDIUMReportIncident DiscussionTools integration causes slow requestsEPSS 0.4%CVE-2025-11243HIGHAllocation of Resources Without Limits or Throttling in Shelly Pro 4PMEPSS 0.4%CVE-2026-77121MEDIUMNexus Repository 3 - Denial of Service via Unbounded Maven POM Metadata FieldsEPSS 0.4%CVE-2024-6600MEDIUMMemory corruption in WebGL APIEPSS 0.4%CVE-2025-11374MEDIUMConsul's KV endpoint is vulnerable to denial of serviceEPSS 0.4%CVE-2025-35965MEDIUMDoS in Mattermost Playbooks via Excessive Task ActionsEPSS 0.4%CVE-2025-11375MEDIUMConsul's event endpoint is vulnerable to denial of serviceEPSS 0.4%CVE-2025-25032HIGHIBM Cognos Analytics denial of serviceEPSS 0.4%CVE-2020-37067HIGHFiletto 1.0 - 'FEAT' Denial of ServiceEPSS 0.4%CVE-2026-15144HIGH@fastify/rate-limit vulnerable to rate-limit bypass via IPv6 address rotationEPSS 0.4%CVE-2026-49870MEDIUMSnipe-IT: TOTP Brute-Forceable Due to Missing Rate Limiting on `POST /two-factor`EPSS 0.4%CVE-2020-10717LOWA potential DoS flaw was found in the virtio-fs shared file system daemon (virtiofsd) implementation of the QEMU version >= v5.0. Virtio-fs EPSS 0.4%CVE-2025-69229MEDIUMAIOHTTP vulnerable to DoS through chunked messagesEPSS 0.4%CVE-2024-6509MEDIUMMarinus Pfund, member of the AXIS OS Bug Bounty Program, has found the VAPIX API alwaysmulti.cgi was vulnerable for file globbing which couEPSS 0.4%CVE-2026-41648MEDIUMIncus: Unbounded YAML Metadata Decode via ParsingEPSS 0.4%CVE-2025-36098MEDIUMIBM Db2 Denial of ServiceEPSS 0.4%