Falhas do tipo CWE-770

1.865 resultados

Alocação de recursos sem limite (negação de serviço por esgotamento)

A aplicação aloca recursos (memória, conexões, arquivos, threads) a pedido de um usuário sem impor limites, permitindo que um atacante esgote todos os recursos disponíveis e derrube o serviço. É basicamente deixar a porta aberta para qualquer um encher a caixa d'água até transbordar.

Exemplo

Um servidor web que cria uma nova thread para cada requisição HTTP recebida, sem limite. Um atacante envia milhares de requisições simultâneas e esgota o pool de threads, tornando o servidor inresponsivo para usuários legítimos — é negação de serviço puro.

Como mitigar

Implemente limites rigorosos: rate limiting (requisições por IP/usuário), quotas de recursos, pool de threads/conexões com tamanho máximo, timeout em operações, e monitoramento de consumo. Valide tamanhos de entrada e rejeite alocações que excedam os limites configurados.

CVE-2024-43708MEDIUMAn allocation of resources without limits or throttling in Kibana can lead to a crash caused by a specially crafted payload to a number of iEPSS 0.4%CVE-2026-24720LOWFile Station 5EPSS 0.4%CVE-2024-52972MEDIUMKibana allocation of resources without limits or throttling leads to crashEPSS 0.4%CVE-2021-0224MEDIUMJunos OS: ANCPD core when hitting maximum-discovery-table-entries limitEPSS 0.4%CVE-2026-1458MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.4%CVE-2026-1456MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.4%CVE-2023-54394MEDIUMPocketMine-MP before 4.18.0-ALPHA2 Bandwidth Amplification via InventoryTransactionPacketEPSS 0.4%CVE-2026-41173MEDIUMUnbounded HTTP response body read in OpenTelemetry.Sampler.AWSEPSS 0.4%CVE-2025-54575MEDIUMImageSharp Triggers an Infinite Loop in its GIF Decoder When Skipping Malformed Comment Extension BlocksEPSS 0.4%CVE-2025-68390MEDIUMElasticsearch Allocation of Resources Without Limits or ThrottlingEPSS 0.4%CVE-2026-78383HIGHApache Tomcat: AJP DoS via missing request bodyEPSS 0.4%CVE-2026-45023MEDIUMAutoGPT: Credit system bypassed via direct block execution in POST /api/blocks/{block_id}/executeEPSS 0.4%CVE-2025-52570LOWLetmein connection limiter allows an arbitrary amount of simultaneous connectionsEPSS 0.4%CVE-2026-41483MEDIUMUnbounded HTTP response body read in OpenTelemetry.Resources.AzureEPSS 0.4%CVE-2026-100660HIGHNetty before 4.2.18.Final QpackEncoder Unbounded Memory RetentionEPSS 0.4%CVE-2024-35969HIGHipv6: fix race condition between ipv6_get_ifaddr and ipv6_del_addrEPSS 0.4%CVE-2021-25671—A vulnerability has been identified in RWG1.M12 (All versions < V1.16.16), RWG1.M12D (All versions < V1.16.16), RWG1.M8 (All versions < V1.1EPSS 0.4%CVE-2026-43678MEDIUMAn unauthenticated remote peer can crash any NIOWebSocket-based server (including Vapor and Hummingbird) with a single 11-byte frame sent afEPSS 0.4%CVE-2022-3456MEDIUMAllocation of Resources Without Limits or Throttling in ikus060/rdiffwebEPSS 0.4%CVE-2021-3527—A flaw was found in the USB redirector device (usb-redir) of QEMU. Small USB packets are combined into a single, large transfer request, to EPSS 0.4%