Falhas do tipo CWE-770

1.866 resultados

Alocação de recursos sem limite (negação de serviço por esgotamento)

A aplicação aloca recursos (memória, conexões, arquivos, threads) a pedido de um usuário sem impor limites, permitindo que um atacante esgote todos os recursos disponíveis e derrube o serviço. É basicamente deixar a porta aberta para qualquer um encher a caixa d'água até transbordar.

Exemplo

Um servidor web que cria uma nova thread para cada requisição HTTP recebida, sem limite. Um atacante envia milhares de requisições simultâneas e esgota o pool de threads, tornando o servidor inresponsivo para usuários legítimos — é negação de serviço puro.

Como mitigar

Implemente limites rigorosos: rate limiting (requisições por IP/usuário), quotas de recursos, pool de threads/conexões com tamanho máximo, timeout em operações, e monitoramento de consumo. Valide tamanhos de entrada e rejeite alocações que excedam os limites configurados.

CVE-2026-19517MEDIUMImproper Validation of Specified Quantity in Input and Allocation of Resources Without Limits or Throttling vulnerability in Samsung Open SoEPSS 0.4%CVE-2025-3734MEDIUMStage File Proxy - Moderately critical - Denial of Service - SA-CONTRIB-2025-035EPSS 0.4%CVE-2026-13586MEDIUMPKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS)EPSS 0.4%CVE-2025-64334HIGHSuricata is vulnerable to unbounded memory growth for decompressionEPSS 0.4%CVE-2026-66067MEDIUMRabbitMQ: Stream protocol skips per vhost per user connection limitsEPSS 0.4%CVE-2026-20103HIGHA vulnerability in the Remote Access SSL VPN functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure FiEPSS 0.4%CVE-2026-86065HIGHKlever-Go: Unauthenticated WebSocket /subscribe: no read-size limit, no connection cap, permissive origin -> remote node memory/goroutine exhaustion (DoS)EPSS 0.4%CVE-2026-71540HIGHWazuh Manager cluster header parsing allows pre-authentication memory exhaustionEPSS 0.4%CVE-2021-47895MEDIUMNsauditor 3.2.2.0 - 'Event Description' Denial of ServiceEPSS 0.4%CVE-2025-57705MEDIUMQTS, QuTS heroEPSS 0.3%CVE-2026-66037HIGHFFmpeg IAMF Demuxer Uncontrolled Resource Consumption via mix_presentation_obu()EPSS 0.3%CVE-2026-100658MEDIUMNetty before 4.1.138.Final Denial of Service via WebSocketServerExtensionHandlerEPSS 0.3%CVE-2026-44070LOWUnbounded realloc in charset conversionEPSS 0.3%CVE-2024-45700MEDIUMDoS vulnerability due to uncontrolled resource exhaustionEPSS 0.3%CVE-2025-41430HIGHBIG-IP SSL Orchestrator vulnerabilityEPSS 0.3%CVE-2026-22045MEDIUMTraefik's ACME TLS-ALPN fast path lacks timeouts and close on handshake stallEPSS 0.3%CVE-2026-35202LOWPterodactyl has a database resource limit bypass via race condition in Client APIEPSS 0.3%CVE-2023-29737—An issue found in Wave Animated Keyboard Emoji v.1.70.7 for Android allows a local attacker to cause a denial of service via the database fiEPSS 0.3%CVE-2026-23963MEDIUMMastodon missing length limits on list names, filter names, and filter keywordsEPSS 0.3%CVE-2025-66369HIGHAn issue was discovered in MM in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 2100, 1280, 2200, 1330, 1380,EPSS 0.3%