Falhas do tipo CWE-770

1.865 resultados

Alocação de recursos sem limite (negação de serviço por esgotamento)

A aplicação aloca recursos (memória, conexões, arquivos, threads) a pedido de um usuário sem impor limites, permitindo que um atacante esgote todos os recursos disponíveis e derrube o serviço. É basicamente deixar a porta aberta para qualquer um encher a caixa d'água até transbordar.

Exemplo

Um servidor web que cria uma nova thread para cada requisição HTTP recebida, sem limite. Um atacante envia milhares de requisições simultâneas e esgota o pool de threads, tornando o servidor inresponsivo para usuários legítimos — é negação de serviço puro.

Como mitigar

Implemente limites rigorosos: rate limiting (requisições por IP/usuário), quotas de recursos, pool de threads/conexões com tamanho máximo, timeout em operações, e monitoramento de consumo. Valide tamanhos de entrada e rejeite alocações que excedam os limites configurados.

CVE-2025-9368HIGH432ES-IG3 Series A Denial-of-Service VulnerabilityEPSS 0.4%CVE-2026-18362MEDIUMDFIR-IRIS Missing Brute Force Protection in User AuthenticationEPSS 0.4%CVE-2026-56255MEDIUMCapgo - Denial of Service via Unlimited Demo App CreationEPSS 0.4%CVE-2024-52973MEDIUMKibana allocation of resources without limits or throttling leads to crashEPSS 0.4%CVE-2025-3050MEDIUMIBM Db2 denial of serviceEPSS 0.4%CVE-2026-75841MEDIUMArcadeDB before 26.8.1 Denial of Service via range()EPSS 0.4%CVE-2026-82309MEDIUMRobots::Validate versions from 0.3.2 before 0.3.11 for Perl allow unbounded outbound DNS queries per validation via a forward-confirmation loop that does not bound the names it queriesEPSS 0.4%CVE-2025-36387MEDIUMIBM Db2 Denial of ServiceEPSS 0.4%CVE-2025-3279MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.4%CVE-2025-1000MEDIUMIBM Db2 denial of serviceEPSS 0.4%CVE-2025-4225MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.4%CVE-2026-100600MEDIUMClawHub before 8c2de6c506 Quota Exhaustion via Anonymous APIEPSS 0.4%CVE-2025-54884HIGHVision UI security-kit.js: Potential Uncontrolled Resource Allocation VulnerabilityEPSS 0.4%CVE-2025-2403HIGHA denial-of-service vulnerability due to improper prioritization of network traffic over protection mechanism exists in Relion 670/650 and SEPSS 0.4%CVE-2025-48053HIGHDiscourse vulnerable to DoS via large URL payload in PM to a botEPSS 0.4%CVE-2026-48045MEDIUMZeroconf: Unbounded TC-deferred queue allows LAN-local memory exhaustion via spoofed-source floodEPSS 0.4%CVE-2021-22532HIGHPossible NLDAP Denial of Service attack VulnerabilityEPSS 0.4%CVE-2025-11832CRITICALAPIs Lack Rate LimitingEPSS 0.4%CVE-2023-38543HIGHA vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attackerEPSS 0.4%CVE-2025-62426MEDIUMvLLM vulnerable to DoS via large Chat Completion or Tokenization requests with specially crafted `chat_template_kwargs`EPSS 0.4%