Fallos del tipo CWE-770
1861 resultadosAlocação sem limite de recursos
A aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem impor limites, permitindo que um atacante esgote os recursos do sistema. O risco é negação de serviço: a aplicação ou servidor inteiro pode travar quando os recursos acabam.
Ejemplo
Um servidor web aceita requisições sem limitar quantas conexões simultâneas um único usuário pode abrir, ou um upload sem verificar tamanho máximo. Um atacante abre milhões de conexões ou envia arquivos gigantes até a memória/disco encher.
Cómo mitigar
Implemente quotas e limites por usuário/origem (rate limiting, máximo de conexões simultâneas, tamanho máximo de upload). Monitore consumo de recursos e recuse requisições que violem os limites com erro 429 ou similar.
CVE-2026-34513LOWAIOHTTP: Denial of Service (DoS) via Unbounded DNS Cache in TCPConnectorEPSS 0.6%CVE-2026-59899MEDIUMNetty HttpContentEncoder: Unbounded Per-Connection Queue Growth via HTTP/1.1 Pipelining Leads to Denial of ServiceEPSS 0.6%CVE-2026-91149HIGHCockpit: cockpit: denial of service via unbounded connection thread spawningEPSS 0.6%CVE-2023-33720MEDIUMmp4v2 v2.1.2 was discovered to contain a memory leak via the class MP4BytesProperty.EPSS 0.6%CVE-2026-45713HIGHMailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizesEPSS 0.6%CVE-2026-54063HIGHExcelize: Unbounded Row Index Allocation in Worksheet Parser (checkSheet OOM/Panic DoS)EPSS 0.6%CVE-2021-47865HIGHProFTPD 1.3.7a - Remote Denial of ServiceEPSS 0.6%CVE-2024-31446HIGHOpenComputers Denial of Service using xpcallEPSS 0.6%CVE-2026-23881HIGHKyverno Denial of Service via Context Variable Amplification in Policy EngineEPSS 0.6%CVE-2024-48809HIGHAn issue in Open Networking Foundations sdran-in-a-box v.1.4.3 and onos-a1t v.0.2.3 allows a remote attacker to cause a denial of service viEPSS 0.6%CVE-2024-50311MEDIUMGraphql: denial of service (dos) vulnerability via graphql batchingEPSS 0.6%CVE-2025-2813HIGHHTTP Service DoS VulnerabilityEPSS 0.6%CVE-2025-10497HIGHAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.6%CVE-2026-67317MEDIUMaxios 1.7.0 before 1.18.0 maxBodyLength Bypass via ReadableStreamEPSS 0.6%CVE-2026-55078MEDIUMCoder: Zip upload decompression lacks aggregate size limit, enabling denial of serviceEPSS 0.6%CVE-2023-32481MEDIUM
Wyse Management Suite versions prior to 4.0 contain a denial-of-service vulnerability. An authenticated malicious user can flood the configEPSS 0.6%CVE-2026-45554MEDIUMNiceGUI: Unauthenticated log-flood DoS via trailing slash on ESM and per-component resource routesEPSS 0.6%CVE-2024-31881MEDIUMIBM Db2 denial of serviceEPSS 0.6%CVE-2025-24317MEDIUMAllocation of resources without limits or throttling issue exists in HMI ViewJet C-more series and HMI GC-A2 series, which may allow a remotEPSS 0.6%CVE-2025-8537MEDIUMAxiomatic Bento4 mp4decrypt Mp4Decrypt.cpp SetDataSize allocation of resourcesEPSS 0.6%