Fallos del tipo CWE-770

1855 resultados

Alocação sem limite de recursos

A aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem impor limites, permitindo que um atacante esgote os recursos do sistema. O risco é negação de serviço: a aplicação ou servidor inteiro pode travar quando os recursos acabam.

Ejemplo

Um servidor web aceita requisições sem limitar quantas conexões simultâneas um único usuário pode abrir, ou um upload sem verificar tamanho máximo. Um atacante abre milhões de conexões ou envia arquivos gigantes até a memória/disco encher.

Cómo mitigar

Implemente quotas e limites por usuário/origem (rate limiting, máximo de conexões simultâneas, tamanho máximo de upload). Monitore consumo de recursos e recuse requisições que violem os limites com erro 429 ou similar.

CVE-2026-34045HIGHPodman Desktop WebView Server ExposedEPSS 0.7%CVE-2026-40498HIGHFreeScout has Authentication Bypass and Information Disclosure in SystemController via /system/cronEPSS 0.7%CVE-2026-90584MEDIUMTooTallNate Java-WebSocket Fragmentation Draft_6455.java processFrameContinuousAndNonFin allocation of resourcesEPSS 0.7%CVE-2023-32187HIGHAn Allocation of Resources Without Limits or Throttling vulnerability in SUSE k3s allows attackers with access to K3s servers' apiserver/supEPSS 0.7%CVE-2023-36814HIGHzopefoundation's Products.CMFCore vulnerable to unauthenticated denial of service and crash via unchecked use of input with Python's marshal moduleEPSS 0.7%CVE-2018-15472HIGHAn issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. The diff fEPSS 0.7%CVE-2026-93688HIGHSGLang through 0.5.19 Unbounded Memory Allocation via bootstrap_roomEPSS 0.7%CVE-2023-28356HIGHA vulnerability has been identified where a maliciously crafted message containing a specific chain of characters can cause the chat to enteEPSS 0.7%CVE-2024-38528HIGHUnlimited number of NTS-KE connections can crash ntpd-rs serverEPSS 0.7%CVE-2024-48080HIGHAn issue in aedes v0.51.2 allows attackers to cause a Denial of Service(DoS) via a crafted request. NOTE: the Supplier indicates that exploiEPSS 0.7%CVE-2026-5316MEDIUMNothings stb stb_vorbis.c setup_free allocation of resourcesEPSS 0.7%CVE-2026-42570HIGHSvelte devalue: DoS via sparse array deserializationEPSS 0.7%CVE-2026-44248MEDIUMNetty: Resource exhaustion in MqttDecoderEPSS 0.7%CVE-2026-11972HIGHtarfile opened in streaming mode mishandles EOFEPSS 0.7%CVE-2025-11419HIGHKeycloak: keycloak tls client-initiated renegotiation denial of serviceEPSS 0.7%CVE-2023-6117MEDIUMM-Files REST API allows Denial of ServiceEPSS 0.7%CVE-2026-2581MEDIUMundici is vulnerable to Unbounded Memory Consumption in in Undici's DeduplicationHandler via Response Buffering leads to DoSEPSS 0.7%CVE-2024-9056HIGHDenial of Service in bentoml/bentomlEPSS 0.7%CVE-2024-10650HIGHDenial of Service (DoS) in gaizhenbiao/chuanhuchatgptEPSS 0.7%CVE-2018-16864HIGHAn allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journaEPSS 0.7%