Falhas do tipo CWE-770

1.865 resultados

Alocação de recursos sem limite (negação de serviço por esgotamento)

A aplicação aloca recursos (memória, conexões, arquivos, threads) a pedido de um usuário sem impor limites, permitindo que um atacante esgote todos os recursos disponíveis e derrube o serviço. É basicamente deixar a porta aberta para qualquer um encher a caixa d'água até transbordar.

Exemplo

Um servidor web que cria uma nova thread para cada requisição HTTP recebida, sem limite. Um atacante envia milhares de requisições simultâneas e esgota o pool de threads, tornando o servidor inresponsivo para usuários legítimos — é negação de serviço puro.

Como mitigar

Implemente limites rigorosos: rate limiting (requisições por IP/usuário), quotas de recursos, pool de threads/conexões com tamanho máximo, timeout em operações, e monitoramento de consumo. Valide tamanhos de entrada e rejeite alocações que excedam os limites configurados.

CVE-2025-0695MEDIUMAn Allocation of Resources Without Limits or Throttling vulnerability in Cesanta Frozen versions less than 1.7 allows an attacker to induce EPSS 0.4%CVE-2026-1718HIGHIBM® Db2® is vulnerable to a denial of service with a specially crafted query when running an AUTONOMOUS procedureEPSS 0.4%CVE-2024-21994MEDIUMCVE-2024-21994 Denial of Service Vulnerability in StorageGRID (formerly StorageGRID Webscale)EPSS 0.4%CVE-2020-37085HIGHVirtualTablet Server 3.0.2 - Denial of Service (PoC)EPSS 0.4%CVE-2026-12760HIGHDenial-of-Service Vulnerability via Malformed IPv4 Fragmentation Handling in TP-Link Tapo C200EPSS 0.4%CVE-2026-95666MEDIUMUnbounded post ID array in the bulk reactions endpoint allows denial of serviceEPSS 0.4%CVE-2026-8287MEDIUMUnrestricted File Upload in BizimHesap Information Systems' Online Pre-Accounting SoftwareEPSS 0.4%CVE-2026-19014MEDIUMUncontrolled resource consumption in the Consul Connect authorization endpointEPSS 0.4%CVE-2026-48187MEDIUMEmail with special content can lead to DoSEPSS 0.4%CVE-2026-95845HIGHMoquette unbounded per-session message queues allow memory exhaustionEPSS 0.4%CVE-2020-37143MEDIUMProficySCADA for iOS 5.0.25920 - 'Password' Denial of ServiceEPSS 0.4%CVE-2025-12767MEDIUMMultiple Vulnerabilities in IBM Concert SoftwareEPSS 0.4%CVE-2025-15317MEDIUMTanium addressed an uncontrolled resource consumption vulnerability in Tanium Server.EPSS 0.4%CVE-2026-53493MEDIUMContainerd has image-pull DoS via crafted OCI index graph amplificationEPSS 0.4%CVE-2026-56309MEDIUMCapgo - Plan Bypass via Unrestricted Attachment Upload EndpointEPSS 0.4%CVE-2025-66838MEDIUMIn Aris v10.0.23.0.3587512 and before, the file upload functionality does not enforce any rate limiting or throttling, allowing users to uplEPSS 0.4%CVE-2025-52494HIGHAdacore Ada Web Server (AWS) before 25.2 is vulnerable to a denial-of-service (DoS) condition due to improper handling of SSL handshakes durEPSS 0.4%CVE-2026-19517MEDIUMImproper Validation of Specified Quantity in Input and Allocation of Resources Without Limits or Throttling vulnerability in Samsung Open SoEPSS 0.4%CVE-2022-41845MEDIUMAn issue was discovered in Bento4 1.6.0-639. There ie excessive memory consumption in the function AP4_Array<AP4_ElstEntry>::EnsureCapacity EPSS 0.4%CVE-2026-8683MEDIUMOverly long URLs crash the Mattermost Desktop AppEPSS 0.4%