Fallos del tipo CWE-770
1855 resultadosAlocação sem limite de recursos
A aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem impor limites, permitindo que um atacante esgote os recursos do sistema. O risco é negação de serviço: a aplicação ou servidor inteiro pode travar quando os recursos acabam.
Ejemplo
Um servidor web aceita requisições sem limitar quantas conexões simultâneas um único usuário pode abrir, ou um upload sem verificar tamanho máximo. Um atacante abre milhões de conexões ou envia arquivos gigantes até a memória/disco encher.
Cómo mitigar
Implemente quotas e limites por usuário/origem (rate limiting, máximo de conexões simultâneas, tamanho máximo de upload). Monitore consumo de recursos e recuse requisições que violem os limites com erro 429 ou similar.
CVE-2023-47746MEDIUMIBM Db2 denial of serviceEPSS 0.7%CVE-2023-27596HIGHOpenSIPS has vulnerability in the codec_delete_XX() functionsEPSS 0.7%CVE-2026-71469HIGHAcm-search-v2-api-rhel9: search-v2-api: unbounded tokenreviews cache allows unauthenticated memory-exhaustion dosEPSS 0.7%CVE-2026-50589MEDIUMIn OpenStack Ironic 32 before 37.0.0, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JEPSS 0.7%CVE-2026-33483HIGHAVideo Affected by Unauthenticated Disk Space Exhaustion via Unlimited Temp File Creation in aVideoEncoderChunk.json.phpEPSS 0.7%CVE-2024-45797HIGHLibHTP's unbounded header handling leads to denial serviceEPSS 0.7%CVE-2026-57212HIGHRabbitMQ management HTTP API accepts request bodies larger than configured max_http_body_sizeEPSS 0.7%CVE-2022-1333LOWA specifically drafted Playbook could trigger large amount of webhook requests leading to Denial of ServiceEPSS 0.7%CVE-2026-27571MEDIUMnats-server websockets are vulnerable to pre-auth memory DoSEPSS 0.7%CVE-2024-23820MEDIUMOpenFGA DoSEPSS 0.7%CVE-2026-54225HIGHApache CXF: Denial of Service attack via large attachmentsEPSS 0.7%CVE-2023-4647MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.7%CVE-2023-28882HIGHTrustwave ModSecurity 3.0.5 through 3.0.8 before 3.0.9 allows a denial of service (worker crash and unresponsiveness) because some inputs caEPSS 0.7%CVE-2026-14456HIGHUnbounded Memory Growth in QUIC Server Incoming Channel QueueEPSS 0.7%CVE-2022-31118MEDIUMMissing brute force protection on cloud federation sharing in Nextcloud ServerEPSS 0.7%CVE-2026-44891HIGHNetty: Denial of Service via Unbounded Headers in StompSubframeDecoderEPSS 0.7%CVE-2026-32011HIGHOpenClaw < 2026.3.2 - Slow-Request Denial of Service via Pre-Auth Webhook Body ParsingEPSS 0.7%CVE-2026-32980HIGHOpenClaw < 2026.3.13 - Resource Exhaustion via Unauthenticated Telegram Webhook RequestEPSS 0.7%CVE-2020-36946HIGHSyncBreeze 10.0.28 - 'login' Denial of ServiceEPSS 0.7%CVE-2026-60001MEDIUMsshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.EPSS 0.7%