Falhas do tipo CWE-770

1.866 resultados

Alocação de recursos sem limite (negação de serviço por esgotamento)

A aplicação aloca recursos (memória, conexões, arquivos, threads) a pedido de um usuário sem impor limites, permitindo que um atacante esgote todos os recursos disponíveis e derrube o serviço. É basicamente deixar a porta aberta para qualquer um encher a caixa d'água até transbordar.

Exemplo

Um servidor web que cria uma nova thread para cada requisição HTTP recebida, sem limite. Um atacante envia milhares de requisições simultâneas e esgota o pool de threads, tornando o servidor inresponsivo para usuários legítimos — é negação de serviço puro.

Como mitigar

Implemente limites rigorosos: rate limiting (requisições por IP/usuário), quotas de recursos, pool de threads/conexões com tamanho máximo, timeout em operações, e monitoramento de consumo. Valide tamanhos de entrada e rejeite alocações que excedam os limites configurados.

CVE-2026-16971MEDIUMDFIR-IRIS Missing Brute Force Protection in OTP ValidationEPSS 0.3%CVE-2021-28715MEDIUMGuest can force Linux netback driver to hog large amounts of kernel memory T[his CNA information record relates to multiple CVEs; the text eEPSS 0.3%CVE-2025-47208MEDIUMQTS, QuTS heroEPSS 0.3%CVE-2025-15474MEDIUMAuntyFey Smart Combination Lock BLE Connection Flood DoSEPSS 0.3%CVE-2023-31914MEDIUMJerryscript 3.0 (commit 05dbbd1) was discovered to contain out-of-memory issue in malloc.EPSS 0.3%CVE-2025-29606MEDIUMpy-libp2p before 0.2.3 allows a peer to cause a denial of service (resource consumption) via a large RSA key.EPSS 0.3%CVE-2026-39396LOWOpenBao has Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)EPSS 0.3%CVE-2025-63402MEDIUMAn issue in HCL Technologies Limited HCLTech GRAGON before v.7.6.0 allows a remote attacker to execute arbitrary code via APIs do not enforcEPSS 0.3%CVE-2025-54320MEDIUMIn Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the invite user function, leading to an email bombing vulnerabilitEPSS 0.3%CVE-2026-49337MEDIUMlibde265 has an unbounded memory leak via orphaned slice headers in `read_slice_NAL`EPSS 0.3%CVE-2025-46638HIGHDell BSAFE SSL-J contains an allocation of resources without limits or throttling vulnerability. An unauthenticated remote attacker could poEPSS 0.3%CVE-2025-71411MEDIUMIn CPDLC, Broadcast Control Frames Can Disconnect Multiple Aircraft SimultaneouslyEPSS 0.3%CVE-2025-71410MEDIUMMalicious Link Control Frames Can Cause Loss of CPDLC FunctionsEPSS 0.3%CVE-2025-10867LOWAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.3%CVE-2026-67225MEDIUMRabbitMQ: Stream-protocol frame length never validated against frame_maxEPSS 0.3%CVE-2025-3601MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.3%CVE-2026-22925HIGHA vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application is susceptible to resource exhaustionEPSS 0.3%CVE-2025-68384MEDIUMElasticsearch Allocation of Resources Without Limits or ThrottlingEPSS 0.3%CVE-2025-11482HIGHAllocation of Resources Without Limits or Throttling in the OPC-UA ServerEPSS 0.3%CVE-2025-9177HIGHRockwell Automation 1715 EtherNet/IP Comms Module Denial-Of-Service VulnerabilityEPSS 0.3%