Falhas do tipo CWE-770

1.864 resultados

Alocação de recursos sem limite (negação de serviço por esgotamento)

A aplicação aloca recursos (memória, conexões, arquivos, threads) a pedido de um usuário sem impor limites, permitindo que um atacante esgote todos os recursos disponíveis e derrube o serviço. É basicamente deixar a porta aberta para qualquer um encher a caixa d'água até transbordar.

Exemplo

Um servidor web que cria uma nova thread para cada requisição HTTP recebida, sem limite. Um atacante envia milhares de requisições simultâneas e esgota o pool de threads, tornando o servidor inresponsivo para usuários legítimos — é negação de serviço puro.

Como mitigar

Implemente limites rigorosos: rate limiting (requisições por IP/usuário), quotas de recursos, pool de threads/conexões com tamanho máximo, timeout em operações, e monitoramento de consumo. Valide tamanhos de entrada e rejeite alocações que excedam os limites configurados.

CVE-2025-14466MEDIUMGüralp Systems Fortimus Series, Minimus Series, and Certimus Series have an Allocation of Resources Without Limits or Throttling vulnerabilityEPSS 0.4%CVE-2026-48082LOWOpenReception's bootstrap challenge proof-of-work difficulty hardcoded to 16 bits, which enables abuse rate amplificationEPSS 0.4%CVE-2025-0915MEDIUMIBM Db2 denial of serviceEPSS 0.4%CVE-2026-58661MEDIUMn8n - Disk Space Exhaustion via Data-Table File Upload EndpointEPSS 0.4%CVE-2025-48038MEDIUMUnverified File Handles can Cause Excessive Use of System ResourcesEPSS 0.4%CVE-2025-12576MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.4%CVE-2025-11974MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.4%CVE-2025-48039MEDIUMUnverified Paths can Cause Excessive Use of System ResourcesEPSS 0.4%CVE-2025-13690MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.4%CVE-2025-48041HIGHSSH_FXP_OPENDIR may Lead to Exhaustion of File HandlesEPSS 0.4%CVE-2025-46556MEDIUMMantisBT is Vulnerable to Denial-of-Service (DoS) attack via Excessive Note LengthEPSS 0.4%CVE-2023-33656MEDIUMA memory leak vulnerability exists in NanoMQ 0.17.2. The vulnerability is located in the file message.c. An attacker could exploit this vulnEPSS 0.4%CVE-2024-38316MEDIUMIBM Aspera Shares Denial of ServiceEPSS 0.4%CVE-2020-37134MEDIUMUltraVNC Viewer 1.2.4.0 - 'VNCServer' Denial of ServiceEPSS 0.4%CVE-2026-66761MEDIUMMultiple vulnerabilities in SAP Business AI Platform (Approuter)EPSS 0.4%CVE-2024-52913MEDIUMIn Bitcoin Core before 0.21.0, an attacker could prevent a node from seeing a specific unconfirmed transaction, because transaction re-requeEPSS 0.4%CVE-2024-36378MEDIUMIn JetBrains TeamCity before 2024.03.2 server was susceptible to DoS attacks with incorrect auth tokensEPSS 0.4%CVE-2024-50955HIGHAn issue in how XINJE XD5E-24R and XL5E-16T v3.5.3b handles TCP protocol messages allows attackers to cause a Denial of Service (DoS) via a EPSS 0.4%CVE-2025-32394MEDIUMAutoGPT: There is a DoS vulnerability in AITextSummarizerBlockEPSS 0.4%CVE-2025-32423MEDIUMAutoGPT: There is a DoS vulnerability in ExtractTextInformationBlockEPSS 0.4%