Falhas do tipo CWE-770

1.865 resultados

Alocação de recursos sem limite (negação de serviço por esgotamento)

A aplicação aloca recursos (memória, conexões, arquivos, threads) a pedido de um usuário sem impor limites, permitindo que um atacante esgote todos os recursos disponíveis e derrube o serviço. É basicamente deixar a porta aberta para qualquer um encher a caixa d'água até transbordar.

Exemplo

Um servidor web que cria uma nova thread para cada requisição HTTP recebida, sem limite. Um atacante envia milhares de requisições simultâneas e esgota o pool de threads, tornando o servidor inresponsivo para usuários legítimos — é negação de serviço puro.

Como mitigar

Implemente limites rigorosos: rate limiting (requisições por IP/usuário), quotas de recursos, pool de threads/conexões com tamanho máximo, timeout em operações, e monitoramento de consumo. Valide tamanhos de entrada e rejeite alocações que excedam os limites configurados.

CVE-2026-77633HIGHCloudreve: Storage-quota TOCTOU race allows quota bypass and storage-based denial of serviceEPSS 0.4%CVE-2026-41078MEDIUMOpenTelemetry dotnet: Potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion pathEPSS 0.4%CVE-2026-41710MEDIUMCache Exhaustion in Stateful Retries leads to Denial of ServiceEPSS 0.4%CVE-2020-36950HIGHLaravel Nova 3.7.0 - 'range' DoSEPSS 0.4%CVE-2026-10600MEDIUMDenial of service via unbounded document content extraction in Mattermost ServerEPSS 0.4%CVE-2025-11044HIGHVulnerability on Automation Runtime my cause DoS ConditionsEPSS 0.4%CVE-2026-92560HIGHApache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication in the AMQP 0-10 decoderEPSS 0.4%CVE-2026-59287MEDIUMSpring for GraphQL WebSocket Client Denial of ServiceEPSS 0.4%CVE-2026-71054MEDIUMVulnerability in Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 7u511. Easily exploitable vulneraEPSS 0.4%CVE-2026-47885HIGHSpring Framework maxPartSize Ignored in PartEventHttpMessageReaderEPSS 0.4%CVE-2025-27157MEDIUMMastodon's rate-limits are missing on `/auth/setup`EPSS 0.4%CVE-2025-64702MEDIUMquic-go HTTP/3 QPACK Header Expansion DoSEPSS 0.4%CVE-2025-33039HIGHQsync CentralEPSS 0.4%CVE-2024-45669MEDIUMIBM Security Verify Information Queue denial of serviceEPSS 0.4%CVE-2025-44006HIGHQsync CentralEPSS 0.4%CVE-2025-33040HIGHQsync CentralEPSS 0.4%CVE-2025-44007HIGHQsync CentralEPSS 0.4%CVE-2026-1662HIGHAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.4%CVE-2026-1725MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.4%CVE-2023-25153MEDIUMcontainerd OCI image importer memory exhaustionEPSS 0.4%