Fallos del tipo CWE-770
1852 resultadosAlocação sem limite de recursos
A aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem impor limites, permitindo que um atacante esgote os recursos do sistema. O risco é negação de serviço: a aplicação ou servidor inteiro pode travar quando os recursos acabam.
Ejemplo
Um servidor web aceita requisições sem limitar quantas conexões simultâneas um único usuário pode abrir, ou um upload sem verificar tamanho máximo. Um atacante abre milhões de conexões ou envia arquivos gigantes até a memória/disco encher.
Cómo mitigar
Implemente quotas e limites por usuário/origem (rate limiting, máximo de conexões simultâneas, tamanho máximo de upload). Monitore consumo de recursos e recuse requisições que violem os limites com erro 429 ou similar.
CVE-2023-45130HIGHFrontier opcode SUICIDE touches too many storage values on large contractsEPSS 0.9%CVE-2026-42154HIGHPrometheus: remote read endpoint allows denial of service via crafted snappy payloadEPSS 0.9%CVE-2024-37358HIGHApache James: denial of service through the use of IMAP literalsEPSS 0.9%CVE-2026-3505HIGHUnbounded PGP AEAD chunk size leads to pre-auth resource exhaustion.EPSS 0.9%CVE-2023-22739MEDIUMDiscourse subject to Allocation of Resources Without Limits or ThrottlingEPSS 0.9%CVE-2026-29181HIGHOpenTelemetry-Go multi-value `baggage` header extraction causes excessive allocations (remote dos amplification)EPSS 0.9%CVE-2025-21543MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Packaging). Supported versions that are affected are 8.0.40 aEPSS 0.9%CVE-2026-54428HIGHApache HttpComponents Core: HPackDecoder Unlimited Header List Size Before SETTINGS ACKEPSS 0.9%CVE-2024-38534HIGHSuricata modbus: txs without responses are never freedEPSS 0.9%CVE-2024-48844HIGHDenial of Service, DoSEPSS 0.9%CVE-2026-40192HIGHPillow is vulnerable to a FITS GZIP decompression bombEPSS 0.9%CVE-2026-93491HIGHIo.netty/netty-codec-http: netty: denial of service via unbounded httpservercodec http/1.1 pipeline queueEPSS 0.9%CVE-2024-21060MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Data Dictionary). Supported versions that are affected are 8.EPSS 0.9%CVE-2025-4820MEDIUMIncorrect congestion window growth by optimistic ACKEPSS 0.9%CVE-2025-12562HIGHAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.9%CVE-2026-41284HIGHApache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handlingEPSS 0.9%CVE-2023-25568HIGHBoxo bitswap/server: DOS unbounded persistent memory leakEPSS 0.9%CVE-2024-7983HIGHDenial of Service in open-webui/open-webuiEPSS 0.9%CVE-2023-6476MEDIUMCri-o: pods are able to break out of resource confinement on cgroupv2EPSS 0.9%CVE-2024-20968MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options). Supported versions that are affected are 8.0.34 andEPSS 0.9%