Fallos del tipo CWE-770

1861 resultados

Alocação sem limite de recursos

A aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem impor limites, permitindo que um atacante esgote os recursos do sistema. O risco é negação de serviço: a aplicação ou servidor inteiro pode travar quando os recursos acabam.

Ejemplo

Um servidor web aceita requisições sem limitar quantas conexões simultâneas um único usuário pode abrir, ou um upload sem verificar tamanho máximo. Um atacante abre milhões de conexões ou envia arquivos gigantes até a memória/disco encher.

Cómo mitigar

Implemente quotas e limites por usuário/origem (rate limiting, máximo de conexões simultâneas, tamanho máximo de upload). Monitore consumo de recursos e recuse requisições que violem os limites com erro 429 ou similar.

CVE-2024-48530HIGHAn issue in the Instructor Appointment Availability module of eSoft Planner 3.24.08271-USA allows attackers to cause a Denial of Service (DoEPSS 0.6%CVE-2026-40006HIGHApache IoTDB: Unauthenticated heap-exhaustion DoS via unbounded allocation in IoTDB AirGap pipe receiverEPSS 0.6%CVE-2024-44241CRITICALThe issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1. An attacker may beEPSS 0.6%CVE-2026-22259HIGHSuricata dnp3: unbounded transaction growthEPSS 0.6%CVE-2026-93572HIGHIo.netty/netty-codec-redis: netty: redisarrayaggregator nested resp headers multiply patched preallocation limitsEPSS 0.6%CVE-2026-81624HIGHUndertow-core: undertow: websocketcontainer defaults for buffers and timeouts are infiniteEPSS 0.6%CVE-2026-90668HIGHThe webserver in UnrealIRCd 6.0.5 through 6.2.6 before 6.2.7 does not limit the number of HTTP request headers, which allows remote attackerEPSS 0.6%CVE-2026-53781MEDIUMSummarize < 0.17.0 Disk Exhaustion via Uncapped Media DownloadEPSS 0.6%CVE-2026-44216MEDIUMWasmtime: Panic when allocating a table exceeding the size of the host's address spaceEPSS 0.6%CVE-2026-41399HIGHOpenClaw < 2026.3.28 - Denial of Service via Unbounded Pre-auth WebSocket UpgradesEPSS 0.6%CVE-2025-32031HIGHApollo Gateway Query Planner Vulnerable to Excessive Resource Consumption via Optimization BypassEPSS 0.6%CVE-2024-8391MEDIUMEclipse Vert.x gRPC server does not limit the maximum message sizeEPSS 0.6%CVE-2025-10858HIGHAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.6%CVE-2025-53069MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services). Supported versions that are affected arEPSS 0.6%CVE-2025-54121MEDIUMStarlette has possible denial-of-service vector when parsing large files in multipart formsEPSS 0.6%CVE-2025-51846HIGHCryptPad unbounded WebSocket frame floodEPSS 0.6%CVE-2026-65654HIGHtemporalio/ringpop-go fails to enforce configured label limits on inbound membership gossipEPSS 0.6%CVE-2026-74835HIGHinets,httpd: Memory Exhaustion via Unenforced max_body_size During Chunked Body ReceptionEPSS 0.6%CVE-2026-73214HIGHcoturn allocates a full per-peer SSL/session before verifying the DTLS cookie, enabling source-spoofing/botnet state-exhaustion DoSEPSS 0.6%CVE-2024-47614HIGHasync-graphql vulnerable to Directive OverloadEPSS 0.6%