Falhas do tipo CWE-770

1.861 resultados

Alocação de recursos sem limite (negação de serviço por esgotamento)

A aplicação aloca recursos (memória, conexões, arquivos, threads) a pedido de um usuário sem impor limites, permitindo que um atacante esgote todos os recursos disponíveis e derrube o serviço. É basicamente deixar a porta aberta para qualquer um encher a caixa d'água até transbordar.

Exemplo

Um servidor web que cria uma nova thread para cada requisição HTTP recebida, sem limite. Um atacante envia milhares de requisições simultâneas e esgota o pool de threads, tornando o servidor inresponsivo para usuários legítimos — é negação de serviço puro.

Como mitigar

Implemente limites rigorosos: rate limiting (requisições por IP/usuário), quotas de recursos, pool de threads/conexões com tamanho máximo, timeout em operações, e monitoramento de consumo. Valide tamanhos de entrada e rejeite alocações que excedam os limites configurados.

CVE-2026-67235HIGHRabbitMQ: AMQP 0-9-1 body assembly never validates accumulated sizeEPSS 0.3%CVE-2025-24112MEDIUMThe issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3. Parsing a file may lead to an EPSS 0.3%CVE-2025-48074MEDIUMOpenEXR's Unbounded File Header Values can Lead to Out-Of-Memory ErrorsEPSS 0.3%CVE-2026-67219MEDIUMRabbitMQ: Consistent-hash exchange unbounded weightEPSS 0.3%CVE-2019-25350MEDIUMXMedia Recode 3.4.8.6 - '.m3u' Denial Of ServiceEPSS 0.3%CVE-2024-10307MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.3%CVE-2025-52889LOWIncus vulnerable to DoS through antispoofing nftables firewall rule bypass on bridge networks with ACLsEPSS 0.3%CVE-2022-42314MEDIUMXenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/EPSS 0.3%CVE-2024-26894MEDIUMACPI: processor_idle: Fix memory leak in acpi_processor_power_exit()EPSS 0.3%CVE-2022-42315MEDIUMXenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/EPSS 0.3%CVE-2025-54151MEDIUMQsync CentralEPSS 0.3%CVE-2022-28654MEDIUMis_closing_session() allows users to fill up apport.logEPSS 0.3%CVE-2021-47771MEDIUMRDP Manager 4.9.9.3 - Denial-of-Service (PoC)EPSS 0.3%CVE-2025-54150MEDIUMQsync CentralEPSS 0.3%CVE-2022-42311MEDIUMXenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/EPSS 0.3%CVE-2026-1850HIGHAn authorized user may disable the MongoDB server by issuing a certain type of complex query due to boolean expression simplificationEPSS 0.3%CVE-2022-42312MEDIUMXenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/EPSS 0.3%CVE-2026-1847HIGHMongoDB Server may crash when inserting large documentsEPSS 0.3%CVE-2022-42317MEDIUMXenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/EPSS 0.3%CVE-2022-42313MEDIUMXenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/EPSS 0.3%