Falhas do tipo CWE-770

1.861 resultados

Alocação de recursos sem limite (negação de serviço por esgotamento)

A aplicação aloca recursos (memória, conexões, arquivos, threads) a pedido de um usuário sem impor limites, permitindo que um atacante esgote todos os recursos disponíveis e derrube o serviço. É basicamente deixar a porta aberta para qualquer um encher a caixa d'água até transbordar.

Exemplo

Um servidor web que cria uma nova thread para cada requisição HTTP recebida, sem limite. Um atacante envia milhares de requisições simultâneas e esgota o pool de threads, tornando o servidor inresponsivo para usuários legítimos — é negação de serviço puro.

Como mitigar

Implemente limites rigorosos: rate limiting (requisições por IP/usuário), quotas de recursos, pool de threads/conexões com tamanho máximo, timeout em operações, e monitoramento de consumo. Valide tamanhos de entrada e rejeite alocações que excedam os limites configurados.

CVE-2025-21494MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected aEPSS 0.3%CVE-2026-47859MEDIUMUnbounded memory allocation in RFC6587SyslogDeserializer (octet-counted framing) — remote DoSEPSS 0.3%CVE-2025-36008MEDIUMIBM Db2 denial of serviceEPSS 0.3%CVE-2021-47551HIGHdrm/amd/amdkfd: Fix kernel panic when reset failed and been triggered againEPSS 0.3%CVE-2023-29570MEDIUMCesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_ffi_cb_free at src/mjs_ffi.c. This vulnerability can lead to a DeEPSS 0.3%CVE-2020-36943MEDIUMaSc TimeTables 2021.6.2 - Denial of ServiceEPSS 0.3%CVE-2021-47894MEDIUMManaged Switch Port Mapping Tool 2.85.2 - Denial of ServiceEPSS 0.3%CVE-2021-47893MEDIUMAgataSoft PingMaster Pro 2.1 - Denial of ServiceEPSS 0.3%CVE-2025-43736MEDIUMA Denial Of Service via File Upload (DOS) vulnerability in the Liferay Portal 7.4.3.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2EPSS 0.3%CVE-2025-36140MEDIUMIBM watsonx.data Denial of ServiceEPSS 0.3%CVE-2026-27663HIGHA vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.10), RTUM85 RTU Base (All versions < V26.EPSS 0.3%CVE-2026-24738MEDIUMgmrtd ReadFile Vulnerable to Denial of Service via Excessive TLV Length ValuesEPSS 0.3%CVE-2026-40990MEDIUMUnbounded cache for function definitionsEPSS 0.3%CVE-2026-30961MEDIUMGokapi's File Request MaxSize Limit Bypassed via Multi-Chunk UploadEPSS 0.3%CVE-2024-52917MEDIUMBitcoin Core before 22.0 has a miniupnp infinite loop in which it allocates memory on the basis of random data received over the network, e.EPSS 0.3%CVE-2026-66080MEDIUMRabbitMQ: Super-stream partitions unbounded allocationEPSS 0.3%CVE-2024-48843HIGHDenial of Service, DoSEPSS 0.3%CVE-2024-4029MEDIUMWildfly: no timeout for eap management interface may lead to denial of service (dos)EPSS 0.3%CVE-2022-20489HIGHIn many functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This couEPSS 0.3%CVE-2021-47877MEDIUMGeoGebra Graphing Calculato‪r‬ 6.0.631.0 - Denial Of ServiceEPSS 0.3%