Fallos del tipo CWE-770
1861 resultadosAlocação sem limite de recursos
A aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem impor limites, permitindo que um atacante esgote os recursos do sistema. O risco é negação de serviço: a aplicação ou servidor inteiro pode travar quando os recursos acabam.
Ejemplo
Um servidor web aceita requisições sem limitar quantas conexões simultâneas um único usuário pode abrir, ou um upload sem verificar tamanho máximo. Um atacante abre milhões de conexões ou envia arquivos gigantes até a memória/disco encher.
Cómo mitigar
Implemente quotas e limites por usuário/origem (rate limiting, máximo de conexões simultâneas, tamanho máximo de upload). Monitore consumo de recursos e recuse requisições que violem os limites com erro 429 ou similar.
CVE-2023-25822MEDIUMReportPortal DoS vulnerability on creating a Launch with too many recursively nested elementsEPSS 0.5%CVE-2025-48738MEDIUMAn e-mail flooding vulnerability in StrangeBee TheHive 5.2.0 before 5.2.16, 5.3.0 before 5.3.11, 5.4.0 before 5.4.10, and 5.5.0 before 5.5.1EPSS 0.5%CVE-2024-7803MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.5%CVE-2026-85107MEDIUMNousResearch hermes-agent Electron Main Process main.ts resourceBufferFromUrl allocation of resourcesEPSS 0.5%CVE-2026-87908HIGHmultiparty vulnerable to Denial of Service via unbounded part-header accumulationEPSS 0.5%CVE-2026-31984HIGHDoS through oversized audit log entries in Guardian/CMC before 26.2.0EPSS 0.5%CVE-2026-15975HIGHAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.5%CVE-2026-33232HIGHAutoGPT: Unauthenticated DoS via Disk Space ExhaustionEPSS 0.5%CVE-2021-47793MEDIUMTelegram Desktop 2.9.2 - Denial of Service (PoC)EPSS 0.5%CVE-2024-12379MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.5%CVE-2026-67430MEDIUMMCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize floodEPSS 0.5%CVE-2022-22488MEDIUMIBM OpenBMC denial of serviceEPSS 0.5%CVE-2026-67446MEDIUMMailpit: Thumbnail generation decodes unbounded image dimensions before scalingEPSS 0.5%CVE-2025-12571HIGHAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.5%CVE-2026-52732MEDIUMZEBRA: Mempool transaction admission denial via single-peer inbound queue saturationEPSS 0.5%CVE-2026-34062MEDIUMNimiq has Allocation of Resources Without Limits or Throttling in its libp2p request/responseEPSS 0.5%CVE-2026-59248HIGHUnbounded HPACK/QPACK prefixed-integer decoding in Cowlib causes memory-exhaustion DoSEPSS 0.5%CVE-2026-34517LOWAIOHTTP: Late size enforcement for non-file multipart fields causes memory DoSEPSS 0.5%CVE-2026-81176MEDIUMSvelte devalue: DoS via malformed inputEPSS 0.5%CVE-2026-67447MEDIUMMailpit: SMTP DATA line reader buffers over-limit input before size enforcementEPSS 0.5%