Fallos del tipo CWE-770
1851 resultadosAlocação sem limite de recursos
A aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem impor limites, permitindo que um atacante esgote os recursos do sistema. O risco é negação de serviço: a aplicação ou servidor inteiro pode travar quando os recursos acabam.
Ejemplo
Um servidor web aceita requisições sem limitar quantas conexões simultâneas um único usuário pode abrir, ou um upload sem verificar tamanho máximo. Um atacante abre milhões de conexões ou envia arquivos gigantes até a memória/disco encher.
Cómo mitigar
Implemente quotas e limites por usuário/origem (rate limiting, máximo de conexões simultâneas, tamanho máximo de upload). Monitore consumo de recursos e recuse requisições que violem os limites com erro 429 ou similar.
CVE-2024-41128MEDIUMAction Dispatch has possible ReDoS vulnerability in query parameter filteringEPSS 1.1%CVE-2021-34568HIGHWAGO I/O-Check Service prone to Allocation of Resources Without Limits or ThrottlingEPSS 1.1%CVE-2021-32476—A denial-of-service risk was identified in the draft files area, due to it not respecting user file upload limits. Moodle versions 3.10 to 3EPSS 1.1%CVE-2022-31394HIGHHyperium Hyper before 0.14.19 does not allow for customization of the max_header_list_size method in the H2 third-party software, allowing aEPSS 1.1%CVE-2025-50334HIGHAn issue in Technitium DNS Server v.13.5 allows a remote attacker to cause a denial of service via the rate-limiting componentEPSS 1.1%CVE-2026-9064HIGH389-ds-base: 389-ds-base: unbounded ldap controls count in get_ldapmessage_controls_ext() causes cpu and heap amplification (remote dos)EPSS 1.1%CVE-2025-21518MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.40 aEPSS 1.1%CVE-2022-43686MEDIUMIn Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2, the authTypeConcreteCookieMap table can be filled up causing EPSS 1.1%CVE-2025-21503MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.40 and prior, 8EPSS 1.1%CVE-2025-21505MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services). Supported versions that are affected arEPSS 1.1%CVE-2023-28837MEDIUMWagtail vulnerable to denial-of-service via memory exhaustion when uploading large filesEPSS 1.1%CVE-2026-29168HIGHApache HTTP Server: mod_md unrestricted OCSP responseEPSS 1.1%CVE-2022-21822HIGHNVIDIA FLARE contains a vulnerability in the admin interface, where an un-authorized attacker can cause Allocation of Resources Without LimiEPSS 1.1%CVE-2026-39304HIGHApache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Incorrect handling of TLSv1.3 KeyUpdate can be exploited to cause DoS via OOMEPSS 1.1%CVE-2026-40984HIGHMicrometer HTTP server instrumentations DoS vulnerabilityEPSS 1.1%CVE-2026-42440HIGHApache OpenNLP: OOM DoS via Unbounded Array Allocation in AbstractModelReaderEPSS 1.1%CVE-2026-75050HIGHIn JetBrains YouTrack before 2026.1.13901,
2026.2.17950 doS attack was possible via crafted type parametersEPSS 1.1%CVE-2025-48367HIGHRedis DoS Vulnerability due to bad connection error handlingEPSS 1.1%CVE-2026-33260MEDIUMInsufficient input validation of internal webserverEPSS 1.1%CVE-2026-33257MEDIUMInsufficient input validation of internal webserverEPSS 1.1%