Fallos del tipo CWE-770
1861 resultadosAlocação sem limite de recursos
A aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem impor limites, permitindo que um atacante esgote os recursos do sistema. O risco é negação de serviço: a aplicação ou servidor inteiro pode travar quando os recursos acabam.
Ejemplo
Um servidor web aceita requisições sem limitar quantas conexões simultâneas um único usuário pode abrir, ou um upload sem verificar tamanho máximo. Um atacante abre milhões de conexões ou envia arquivos gigantes até a memória/disco encher.
Cómo mitigar
Implemente quotas e limites por usuário/origem (rate limiting, máximo de conexões simultâneas, tamanho máximo de upload). Monitore consumo de recursos e recuse requisições que violem os limites com erro 429 ou similar.
CVE-2025-30202HIGHData exposure via ZeroMQ on multi-node vLLM deploymentEPSS 0.6%CVE-2021-47137CRITICALnet: lantiq: fix memory corruption in RX ringEPSS 0.6%CVE-2024-50285HIGHksmbd: check outstanding simultaneous SMB operationsEPSS 0.6%CVE-2024-37302HIGHSynapse denial of service through media disk space consumptionEPSS 0.6%CVE-2023-49559LOWAn issue in vektah gqlparser open-source-library v.2.5.10 allows a remote attacker to cause a denial of service via a crafted script to the EPSS 0.6%CVE-2025-8014HIGHAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.6%CVE-2026-1102MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.6%CVE-2026-25804HIGHAntrea has invalid enforcement order for network policy rules caused by integer overflowEPSS 0.6%CVE-2023-51334MEDIUMA lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Cinema Booking System v1.0 allows attackers to send an excessive amouEPSS 0.6%CVE-2024-46667MEDIUMA allocation of resources without limits or throttling in Fortinet FortiSIEM 5.3 all versions, 5.4 all versions, 6.x all versions, 7.0 all vEPSS 0.6%CVE-2026-85584HIGHSiYuan before v3.8.2 Denial of Service via Auth ThrottleEPSS 0.6%CVE-2026-7250HIGHAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.6%CVE-2026-83615HIGHxmldom: Quadratic-memory consumptionEPSS 0.6%CVE-2026-73541HIGHTempo fee sponsorship in mpp bounds each transaction but not aggregate exposure, allowing concurrent sponsor-wallet drainEPSS 0.6%CVE-2024-45662HIGHIBM Safer Payments denial of serviceEPSS 0.6%CVE-2026-63299HIGHStorage volume cross-project move and snapshot restore bypass project disk limitsEPSS 0.6%CVE-2023-32699MEDIUMMeterSphere denial of service vulnerabilityEPSS 0.6%CVE-2023-37934MEDIUMAn allocation of resources without limits or throttling vulnerability [CWE-770] in FortiPAM 1.0 all versions allows an authenticated attackeEPSS 0.6%CVE-2026-24133HIGHjsPDF Affected by Denial of Service (DoS) via Unvalidated BMP Dimensions in BMPDecoderEPSS 0.6%CVE-2024-28870HIGHSuricata uses excessive resource use in malformed ssh traffic parsingEPSS 0.6%