Fallos del tipo CWE-770
1861 resultadosAlocação sem limite de recursos
A aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem impor limites, permitindo que um atacante esgote os recursos do sistema. O risco é negação de serviço: a aplicação ou servidor inteiro pode travar quando os recursos acabam.
Ejemplo
Um servidor web aceita requisições sem limitar quantas conexões simultâneas um único usuário pode abrir, ou um upload sem verificar tamanho máximo. Um atacante abre milhões de conexões ou envia arquivos gigantes até a memória/disco encher.
Cómo mitigar
Implemente quotas e limites por usuário/origem (rate limiting, máximo de conexões simultâneas, tamanho máximo de upload). Monitore consumo de recursos e recuse requisições que violem os limites com erro 429 ou similar.
CVE-2023-38405—On Crestron 3-Series Control Systems before 1.8001.0187, crafting and sending a specific BACnet packet can cause a crash.EPSS 0.6%CVE-2024-11316HIGHFilesize CheckEPSS 0.6%CVE-2026-59886HIGHpyasn1: Uncontrolled resource consumption when converting decoded REAL valuesEPSS 0.6%CVE-2024-0081HIGH
NVIDIA NeMo framework for Ubuntu contains a vulnerability in tools/asr_webapp where an attacker may cause an allocation of resources withouEPSS 0.6%CVE-2026-45765HIGHSuricata dnp3: unbounded reassembly can lead to resource exhaustionEPSS 0.6%CVE-2026-28461HIGHOpenClaw < 2026.3.1 - Unbounded Memory Growth in Zalo Webhook via Query String Key ChurnEPSS 0.6%CVE-2026-53965MEDIUMMCP PHP SDK: Unbounded SSE buffer in HttpTransport enables client-side denial of serviceEPSS 0.6%CVE-2023-41042MEDIUMDiscourse DoS via remote theme assetsEPSS 0.6%CVE-2025-29786HIGHMemory Exhaustion in Expr Parser with Unrestricted InputEPSS 0.6%CVE-2024-30249HIGHCloudburst Network DoS in RakNet connection handlingEPSS 0.6%CVE-2026-71310MEDIUMrclone: Unbounded HTTP CONNECT Response Headers Can Exhaust rclone MemoryEPSS 0.6%CVE-2026-44253MEDIUMWazuh: Cluster Protocol Memory Exhaustion (DoS) via unbounded receive_str allocation and div_msg_box accumulationEPSS 0.6%CVE-2026-49146HIGHApp::Ack versions before 3.10.0 for Perl allow memory exhaustion via an unbounded context value in a project .ackrcEPSS 0.6%CVE-2026-11586HIGHWS Auto-PONG memory exhaustionEPSS 0.6%CVE-2026-34513LOWAIOHTTP: Denial of Service (DoS) via Unbounded DNS Cache in TCPConnectorEPSS 0.6%CVE-2026-29112HIGH@dicebear/converter vulnerable to ncontrolled memory allocation via crafted SVG dimensionsEPSS 0.6%CVE-2026-25800HIGHquinn-proto has remote memory exhaustion from unbounded out-of-order stream reassemblyEPSS 0.6%CVE-2026-63495HIGHLibevent: Unbounded memory accumulation in WebSocket server via fragmented framesEPSS 0.6%CVE-2026-86075HIGHn8n: Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration EndpointEPSS 0.6%CVE-2026-82399HIGHCoreDNS: Unauthenticated memory exhaustion in custom transportsEPSS 0.6%