Falhas do tipo CWE-770

1.867 resultados

Alocação de recursos sem limite (negação de serviço por esgotamento)

A aplicação aloca recursos (memória, conexões, arquivos, threads) a pedido de um usuário sem impor limites, permitindo que um atacante esgote todos os recursos disponíveis e derrube o serviço. É basicamente deixar a porta aberta para qualquer um encher a caixa d'água até transbordar.

Exemplo

Um servidor web que cria uma nova thread para cada requisição HTTP recebida, sem limite. Um atacante envia milhares de requisições simultâneas e esgota o pool de threads, tornando o servidor inresponsivo para usuários legítimos — é negação de serviço puro.

Como mitigar

Implemente limites rigorosos: rate limiting (requisições por IP/usuário), quotas de recursos, pool de threads/conexões com tamanho máximo, timeout em operações, e monitoramento de consumo. Valide tamanhos de entrada e rejeite alocações que excedam os limites configurados.

CVE-2024-10085HIGHCWE-770: Allocation of Resources Without Limits or Throttling vulnerability exists that could cause denial of service of the OPC UA communicEPSS 0.3%CVE-2025-36099MEDIUMIBM WebSphere Application Server denial of serviceEPSS 0.3%CVE-2026-1500MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.3%CVE-2025-36171MEDIUMIBM Aspera Faspex denial of serviceEPSS 0.3%CVE-2026-66079HIGHRabbitMQ: Pre-auth AMQP 1.0 array32 zero-width element DoSEPSS 0.3%CVE-2025-58578LOWUnlimited user creation by authorized usersEPSS 0.3%CVE-2024-21174LOWVulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.23, 21.3-21.14 and 23.4EPSS 0.3%CVE-2026-0530MEDIUMAllocation of Resources Without Limits or Throttling in Kibana Leading to Excessive AllocationEPSS 0.3%CVE-2026-19472HIGHRockwell Automation ArmorStart® LT Denial Of ServiceEPSS 0.3%CVE-2025-52917MEDIUMThe Yealink RPS API before 2025-05-26 lacks rate limiting, potentially enabling information disclosure via excessive requests.EPSS 0.3%CVE-2024-6504MEDIUMRapid7 InsightVM Protection Mechanism FailureEPSS 0.3%CVE-2025-43752MEDIUMLiferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.EPSS 0.3%CVE-2025-12385HIGHImproper validation of <img> tag size in Text component parserEPSS 0.3%CVE-2026-0398MEDIUMCrafted zones can lead to increased resource usage and crafted CNAME chains can lead to cache poisoning in RecursorEPSS 0.3%CVE-2025-64509HIGHBugsink vulnerable to unauthenticated remote DoS via crafted Brotli input (via CPU)EPSS 0.3%CVE-2024-54501MEDIUMThe issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, macOS SonoEPSS 0.3%CVE-2025-11042MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.3%CVE-2025-68389MEDIUMKibana Allocation of Resources Without Limits or ThrottlingEPSS 0.3%CVE-2025-3525MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.3%CVE-2025-14157MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.3%