Fallos del tipo CWE-770
1852 resultadosAlocação sem limite de recursos
A aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem impor limites, permitindo que um atacante esgote os recursos do sistema. O risco é negação de serviço: a aplicação ou servidor inteiro pode travar quando os recursos acabam.
Ejemplo
Um servidor web aceita requisições sem limitar quantas conexões simultâneas um único usuário pode abrir, ou um upload sem verificar tamanho máximo. Um atacante abre milhões de conexões ou envia arquivos gigantes até a memória/disco encher.
Cómo mitigar
Implemente quotas e limites por usuário/origem (rate limiting, máximo de conexões simultâneas, tamanho máximo de upload). Monitore consumo de recursos e recuse requisições que violem os limites com erro 429 ou similar.
CVE-2024-52797MEDIUMSearching Opencast may cause a denial of serviceEPSS 0.9%CVE-2023-37279HIGHFaktory Web Dashboard can lead to denial of service(DOS) via malicious user inputEPSS 0.9%CVE-2026-25535HIGHjsPDF Affected by Client-Side/Server-Side Denial of Service via Malicious GIF DimensionsEPSS 0.9%CVE-2023-25171HIGHKiwi TCMS has denial of service vulnerability on Password reset pageEPSS 0.9%CVE-2020-14322—In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, yui_combo needed to limit the amount of files it can load to help mitigate the risk of deniEPSS 0.9%CVE-2024-43410HIGHRussh has an OOM Denial of Service due to allocation of untrusted amountEPSS 0.9%CVE-2026-48853CRITICALRemote code execution and denial of service via unsafe Erlang term deserialization in elixir-grpc/grpcEPSS 0.9%CVE-2023-25156HIGHKiwi TCMS has no protection against brute-force attacks on login pageEPSS 0.9%CVE-2023-40019HIGHFreeSWITCH allows authorized users to cause a denial of service attack by sending re-INVITE with SDP containing duplicate codec namesEPSS 0.9%CVE-2023-6910MEDIUMUncontrolled Resource Consumption in M-Files ServerEPSS 0.9%CVE-2026-5807HIGHVault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey OperationsEPSS 0.9%CVE-2022-3480HIGHDenial-of-Service vulnerability in PHOENIX CONTACT mGuard product familyEPSS 0.9%CVE-2022-34439MEDIUMDell PowerScale OneFS, versions 8.2.0.x-9.4.0.x contain allocation of Resources Without Limits or Throttling vulnerability. A remote unautheEPSS 0.9%CVE-2025-7070MEDIUMIROAD Dashcam Q9 MFA Pairing Request allocation of resourcesEPSS 0.9%CVE-2023-29479MEDIUMRibose RNP before 0.16.3 may hang when the input is malformed.EPSS 0.9%CVE-2024-26308MEDIUMApache Commons Compress: OutOfMemoryError unpacking broken Pack200 fileEPSS 0.9%CVE-2026-49361HIGHApache Fluss Netty Frame Decoder Memory Exhaustion VulnerabilityEPSS 0.9%CVE-2026-5497HIGHUnbounded Frame Count in video/jpeg Base64 Data URL Processing Leads to OOM DoS in vllm-project/vllmEPSS 0.9%CVE-2024-35202HIGHBitcoin Core before 25.0 allows remote attackers to cause a denial of service (blocktxn message-handling assertion and node exit) by includiEPSS 0.9%CVE-2026-23538HIGHFeast: resource exhaustion via websocket endpointEPSS 0.9%