Fallos del tipo CWE-770
1861 resultadosAlocação sem limite de recursos
A aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem impor limites, permitindo que um atacante esgote os recursos do sistema. O risco é negação de serviço: a aplicação ou servidor inteiro pode travar quando os recursos acabam.
Ejemplo
Um servidor web aceita requisições sem limitar quantas conexões simultâneas um único usuário pode abrir, ou um upload sem verificar tamanho máximo. Um atacante abre milhões de conexões ou envia arquivos gigantes até a memória/disco encher.
Cómo mitigar
Implemente quotas e limites por usuário/origem (rate limiting, máximo de conexões simultâneas, tamanho máximo de upload). Monitore consumo de recursos e recuse requisições que violem os limites com erro 429 ou similar.
CVE-2026-33592HIGHFindServers Memory Exhaustion in open62541EPSS 0.5%CVE-2026-27869MEDIUMWEB SERVICE (HTTP) DENIAL OF SERVICE VIA SLOW HEADERS ON REGESTA SMART HD-PLC OF TELDATEPSS 0.5%CVE-2026-77409HIGHRabbitMQ amqp091-go: Denial of Service via Synchronous Event Channel BlockingEPSS 0.5%CVE-2026-11946HIGHGetEndpoints Memory Exhaustion in open62541EPSS 0.5%CVE-2026-48862HIGHUnbounded conn.streams growth in Mint HTTP/2 client via unenforced PUSH_PROMISE concurrencyEPSS 0.5%CVE-2024-6826MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.5%CVE-2025-70071MEDIUMAn issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXParser.cpp, ParseVectorDataArray()EPSS 0.5%CVE-2025-13929HIGHAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.5%CVE-2025-59089MEDIUMPython-kdcproxy: remote dos via unbounded tcp upstream bufferingEPSS 0.5%CVE-2026-47891CRITICALSpring Framework maxInMemorySize Bypassed in Jaxb2DecoderEPSS 0.5%CVE-2025-53629HIGHcpp-httplib Unbounded Memory Allocation in Chunked/No-Length Requests VulnerabilityEPSS 0.5%CVE-2024-58259HIGHRancher affected by unauthenticated Denial of ServiceEPSS 0.5%CVE-2026-93309MEDIUMO-RAN-SC SMO OAM VES Collector allocation of resourcesEPSS 0.5%CVE-2026-67297HIGHFreeRDP before 3.29.0 Resource Exhaustion via chunked HTTP responseEPSS 0.5%CVE-2026-93308MEDIUMO-RAN-SC SMO OAM VES Collector allocation of resourcesEPSS 0.5%CVE-2026-67199HIGHPerspective 5.0.0 DoS via Loop Expression EvaluationEPSS 0.5%CVE-2026-42256MEDIUMnet-imap: Denial of service via high iteration count for `SCRAM-*` authenticationEPSS 0.5%CVE-2026-55646MEDIUMvLLM speech-to-text endpoints allocate full upload before enforcing the audio file-size limitEPSS 0.5%CVE-2026-82075HIGHUncontrolled Resource Consumption in MongoDB Sharded Cluster Router Allows Unauthenticated Denial of ServiceEPSS 0.5%CVE-2024-10713HIGHDenial of Service (DoS) via Multipart Request in szad670401/hyperlprEPSS 0.5%