Fallos del tipo CWE-770

1855 resultados

Alocação sem limite de recursos

A aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem impor limites, permitindo que um atacante esgote os recursos do sistema. O risco é negação de serviço: a aplicação ou servidor inteiro pode travar quando os recursos acabam.

Ejemplo

Um servidor web aceita requisições sem limitar quantas conexões simultâneas um único usuário pode abrir, ou um upload sem verificar tamanho máximo. Um atacante abre milhões de conexões ou envia arquivos gigantes até a memória/disco encher.

Cómo mitigar

Implemente quotas e limites por usuário/origem (rate limiting, máximo de conexões simultâneas, tamanho máximo de upload). Monitore consumo de recursos e recuse requisições que violem os limites com erro 429 ou similar.

CVE-2026-28299HIGHSolarWinds Web Help Desk Denial-of-Service VulnerabilityEPSS 0.7%CVE-2023-26249HIGHKnot Resolver before 5.6.0 enables attackers to consume its resources, launching amplification attacks and potentially causing a denial of sEPSS 0.7%CVE-2026-45031MEDIUMImageMagick: Policy Bypass in PSD decoderEPSS 0.7%CVE-2024-26265MEDIUMThe Image Uploader module in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported versions, and Liferay DXP 7.4 before update 16, 7.EPSS 0.7%CVE-2026-67585HIGHAtom Exhaustion via _entities Representation Keys in DivvyPayHQ absinthe_federationEPSS 0.7%CVE-2025-57810HIGHjsPDF Parsing of Corrupt PNGs Leads to Potential Denial of Service (DoS)EPSS 0.7%CVE-2025-0182HIGHDenial of Service in danswer-ai/danswerEPSS 0.7%CVE-2026-32280HIGHUnexpected work during chain building in crypto/x509EPSS 0.7%CVE-2024-37309MEDIUMClient initialized Session-Renegotiation DoSEPSS 0.7%CVE-2023-25414MEDIUMAten PE8108 2.4.232 is vulnerable to denial of service (DOS).EPSS 0.7%CVE-2023-46130MEDIUMBypassing height value allowed in some theme componentsEPSS 0.7%CVE-2023-32186HIGHA Allocation of Resources Without Limits or Throttling vulnerability in SUSE RKE2 allows attackers with access to K3s servers apiserver/supEPSS 0.7%CVE-2026-93310MEDIUMO-RAN-SC SMO OAM VES Collector allocation of resourcesEPSS 0.7%CVE-2024-36403MEDIUMDenial of service/high operating costs through unauthenticated downloads in Matrix Media RepoEPSS 0.7%CVE-2026-86513MEDIUMjava-json-tools jackson-coreutils JSON Pointer parser TreePointer.java TreePointer.tokensFromInput allocation of resourcesEPSS 0.7%CVE-2026-47067HIGHAtom table exhaustion via unrecognized URL schemes in hackneyEPSS 0.7%CVE-2026-45768HIGHSuricata ldap: unbounded responses per transaction can lead to resource exhaustionEPSS 0.7%CVE-2026-57227HIGHSuricata mqtt: unbounded resource consumption from repeated pubrec and pubrel messagesEPSS 0.7%CVE-2026-42793HIGHAtom table exhaustion via attacker-controlled GraphQL SDL names in absintheEPSS 0.7%CVE-2026-93488HIGHIo.netty/netty-codec-http: netty: denial of service via unbounded concurrent spdy streamsEPSS 0.7%