Falhas do tipo CWE-770

1.864 resultados

Alocação de recursos sem limite (negação de serviço por esgotamento)

A aplicação aloca recursos (memória, conexões, arquivos, threads) a pedido de um usuário sem impor limites, permitindo que um atacante esgote todos os recursos disponíveis e derrube o serviço. É basicamente deixar a porta aberta para qualquer um encher a caixa d'água até transbordar.

Exemplo

Um servidor web que cria uma nova thread para cada requisição HTTP recebida, sem limite. Um atacante envia milhares de requisições simultâneas e esgota o pool de threads, tornando o servidor inresponsivo para usuários legítimos — é negação de serviço puro.

Como mitigar

Implemente limites rigorosos: rate limiting (requisições por IP/usuário), quotas de recursos, pool de threads/conexões com tamanho máximo, timeout em operações, e monitoramento de consumo. Valide tamanhos de entrada e rejeite alocações que excedam os limites configurados.

CVE-2026-41648MEDIUMIncus: Unbounded YAML Metadata Decode via ParsingEPSS 0.4%CVE-2026-41685MEDIUMIncus: Unbounded binary import disk exhaustionEPSS 0.4%CVE-2024-10468CRITICALPotential race conditions in IndexedDB could have caused memory corruption, leading to a potentially exploitable crash. This vulnerability aEPSS 0.4%CVE-2026-1224MEDIUMTanium addressed an uncontrolled resource consumption vulnerability in Discover.EPSS 0.4%CVE-2024-47509HIGHJunos OS Evolved: Specific low privileged CLI commands and SNMP GET requests can trigger a resource leak #3EPSS 0.4%CVE-2025-32374MEDIUMPossible Denial of Service (DoS) in DNN.PLATFORM registrationEPSS 0.4%CVE-2024-47508HIGHJunos OS Evolved: Specific low privileged CLI commands and SNMP GET requests can trigger a resource leak #2EPSS 0.4%CVE-2024-31880MEDIUMIBM Db2 denial of serviceEPSS 0.4%CVE-2024-47505HIGHJunos OS Evolved: Specific low privileged CLI commands and SNMP GET requests can trigger a resource leak #1EPSS 0.4%CVE-2026-88382HIGHhiredis commit 29ea279 (post-v1.5.0) contains an uncontrolled memory allocation vulnerability in its RESP aggregate parser.EPSS 0.4%CVE-2024-8973MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.4%CVE-2025-68133HIGHEVerest's unlimited connections can lead to DoS through operating system resource exhaustionEPSS 0.4%CVE-2026-47184MEDIUMZeroconf: Unbounded DNS record cache allows LAN-local memory exhaustion via multicast floodEPSS 0.4%CVE-2025-43762MEDIUMLiferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.EPSS 0.4%CVE-2025-58474MEDIUMBIG-IP Advanced WAF and ASM and NGINX App Protect DNS lookup vulnerabilityEPSS 0.4%CVE-2025-8396MEDIUMInsufficiently specific bounds checking on authorization header could lead to denial of service in the Temporal server on all platforms due EPSS 0.4%CVE-2025-66560MEDIUMQuarkus REST has potential worker thread starvation when HTTP connection is closed while waiting to writeEPSS 0.4%CVE-2025-54572MEDIUMRuby SAML DOS vulnerability with large SAML responseEPSS 0.4%CVE-2025-14466MEDIUMGüralp Systems Fortimus Series, Minimus Series, and Certimus Series have an Allocation of Resources Without Limits or Throttling vulnerabilityEPSS 0.4%CVE-2025-2614MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.4%