Falhas do tipo CWE-770

1.866 resultados

Alocação de recursos sem limite (negação de serviço por esgotamento)

A aplicação aloca recursos (memória, conexões, arquivos, threads) a pedido de um usuário sem impor limites, permitindo que um atacante esgote todos os recursos disponíveis e derrube o serviço. É basicamente deixar a porta aberta para qualquer um encher a caixa d'água até transbordar.

Exemplo

Um servidor web que cria uma nova thread para cada requisição HTTP recebida, sem limite. Um atacante envia milhares de requisições simultâneas e esgota o pool de threads, tornando o servidor inresponsivo para usuários legítimos — é negação de serviço puro.

Como mitigar

Implemente limites rigorosos: rate limiting (requisições por IP/usuário), quotas de recursos, pool de threads/conexões com tamanho máximo, timeout em operações, e monitoramento de consumo. Valide tamanhos de entrada e rejeite alocações que excedam os limites configurados.

CVE-2024-23979HIGHBIG-IP SSL Client Certificate LDAP and CRLDP Authentication profiles vulnerabilityEPSS 0.3%CVE-2025-59459MEDIUMDenial-of-service (DoS) via resource consumptionEPSS 0.3%CVE-2026-7776HIGHBoundary Workers Vulnerable to Denial of Service During TLS HandshakeEPSS 0.3%CVE-2025-65942LOWVictoriaMetrics Snappy Decoder DoS Vulnerability is Causing OOMEPSS 0.3%CVE-2025-59045HIGHStalwart vulnerable to Memory Exhaustion via CalDAV Event ExpansionEPSS 0.3%CVE-2026-29795MEDIUMstellar-xdr: `StringM::from_str` bypasses max length validationEPSS 0.3%CVE-2026-15055MEDIUMPKCS#8 / PBES2 decryptors honour unbounded KDF cost from inputEPSS 0.3%CVE-2025-14870HIGHAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.3%CVE-2026-6060MEDIUMPossible DoS via SQL BoxEPSS 0.3%CVE-2025-61775MEDIUMVickey's unexpired email confirmation link can be reused to send repeated confirmation emailsEPSS 0.3%CVE-2026-82439CRITICALApache Storm DRPC: Unauthenticated Unbounded Memory Growth in DRPCEPSS 0.3%CVE-2026-45712MEDIUMMailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write)EPSS 0.3%CVE-2026-0897HIGHDenial of Service in Keras via Excessive Memory Allocation in HDF5 MetadataEPSS 0.3%CVE-2025-59778HIGHVELOS partition container network vulnerabilityEPSS 0.3%CVE-2024-4781MEDIUMA denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to cEPSS 0.3%CVE-2025-49000LOWInvenTree has uncontrolled memory allocation via built-in label-sheet pluginEPSS 0.3%CVE-2026-27932HIGHjoserfc PBES2 p2c Unbounded Iteration Count enables Denial of Service (DoS)EPSS 0.3%CVE-2025-55199MEDIUMHelm Charts with Specific JSON Schema Values Can Cause Memory ExhaustionEPSS 0.3%CVE-2025-61595HIGHMANTRA tx gas limit is not enforced in send hooksEPSS 0.3%CVE-2025-66487LOWMultiple vulnerabilities have been addressed in IBM Aspera SharesEPSS 0.3%