Falhas do tipo CWE-770

1.861 resultados

Alocação de recursos sem limite (negação de serviço por esgotamento)

A aplicação aloca recursos (memória, conexões, arquivos, threads) a pedido de um usuário sem impor limites, permitindo que um atacante esgote todos os recursos disponíveis e derrube o serviço. É basicamente deixar a porta aberta para qualquer um encher a caixa d'água até transbordar.

Exemplo

Um servidor web que cria uma nova thread para cada requisição HTTP recebida, sem limite. Um atacante envia milhares de requisições simultâneas e esgota o pool de threads, tornando o servidor inresponsivo para usuários legítimos — é negação de serviço puro.

Como mitigar

Implemente limites rigorosos: rate limiting (requisições por IP/usuário), quotas de recursos, pool de threads/conexões com tamanho máximo, timeout em operações, e monitoramento de consumo. Valide tamanhos de entrada e rejeite alocações que excedam os limites configurados.

CVE-2022-20489HIGHIn many functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This couEPSS 0.3%CVE-2025-24086MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, mEPSS 0.3%CVE-2025-0122MEDIUMPrisma SD-WAN: Denial of Service (DoS) Vulnerability Through Burst of Crafted PacketsEPSS 0.3%CVE-2026-24458HIGHDoS attack via login attempts with multi-megabyte passwordsEPSS 0.3%CVE-2025-68934MEDIUMDiscourse Has Denial of Service (DoS) Vulnerability in Drafts Creation EndpointEPSS 0.3%CVE-2026-1848HIGHConnections received from the proxy port may not count towards total accepted connectionsEPSS 0.3%CVE-2026-96764MEDIUMkvcache-ai mooncake Regular Expression GetReplicaListByRegex allocation of resourcesEPSS 0.3%CVE-2022-20492HIGHIn many functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This couEPSS 0.3%CVE-2022-20490HIGHIn multiple functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. ThisEPSS 0.3%CVE-2026-22018LOWVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: LibrariEPSS 0.3%CVE-2026-44247MEDIUMVolcano: Webhook server vulnerable to OOM due to unbounded HTTP request body sizeEPSS 0.3%CVE-2025-29917MEDIUMSuricata decode_base64: signature can do large memory allocationEPSS 0.3%CVE-2025-29916MEDIUMSuricata datasets: ruleset declared settings can lead to resource starvationEPSS 0.3%CVE-2025-31990MEDIUMHCL DevOps Velocity is susceptible to a Denial of Service vulnerabilityEPSS 0.3%CVE-2026-48990MEDIUMjoserfc: b64=false RFC7797 JWS payloads bypass JWSRegistry payload-size limits during deserializationEPSS 0.3%CVE-2026-54429MEDIUMA vulnerability has been identified in SIMATIC S7-PLCSIM Advanced (All versions). Affected devices do not properly handle high-volume multicEPSS 0.3%CVE-2024-5209MEDIUMA denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to dEPSS 0.3%CVE-2024-6004MEDIUMA denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to dEPSS 0.3%CVE-2024-5210MEDIUMA denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to pEPSS 0.3%CVE-2026-94455HIGHUnauthenticated /enterprise/create-user mints lifetime top-tier organizations and discloses their API keyEPSS 0.3%