Fallos del tipo CWE-770
1861 resultadosAlocação sem limite de recursos
A aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem impor limites, permitindo que um atacante esgote os recursos do sistema. O risco é negação de serviço: a aplicação ou servidor inteiro pode travar quando os recursos acabam.
Ejemplo
Um servidor web aceita requisições sem limitar quantas conexões simultâneas um único usuário pode abrir, ou um upload sem verificar tamanho máximo. Um atacante abre milhões de conexões ou envia arquivos gigantes até a memória/disco encher.
Cómo mitigar
Implemente quotas e limites por usuário/origem (rate limiting, máximo de conexões simultâneas, tamanho máximo de upload). Monitore consumo de recursos e recuse requisições que violem os limites com erro 429 ou similar.
CVE-2026-59248HIGHUnbounded HPACK/QPACK prefixed-integer decoding in Cowlib causes memory-exhaustion DoSEPSS 0.5%CVE-2025-0993HIGHAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.5%CVE-2026-25579CRITICALNavidrome affected by Denial of Service and disk exhaustion via oversized `size` parameter in `/rest/getCoverArt` and `/share/img/<token>` endpointsEPSS 0.5%CVE-2026-81699HIGHopenssl_encrypt before 1.4.9 Denial of Service via unbounded KDF costEPSS 0.5%CVE-2024-45526MEDIUMAn issue was discovered in OPC Foundation OPCFoundation/UA-.NETStandard through 1.5.374.78. A remote attacker can send requests with invalidEPSS 0.5%CVE-2024-21539HIGHVersions of the package @eslint/plugin-kit before 0.2.3 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper inputEPSS 0.5%CVE-2026-59246MEDIUMZero-length HTTP/2 CONTINUATION frames bypass Mint's header-block byte-size cap and exhaust client memoryEPSS 0.5%CVE-2026-58229HIGHUnbounded HTTP/1 response-header and chunked-trailer accumulation in Mint causes memory-exhaustion DoSEPSS 0.5%CVE-2026-56149MEDIUMAllocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of ServiceEPSS 0.5%CVE-2024-34703HIGHBotan Vulnerable to Denial of Service Due to Overly Large Elliptic Curve ParametersEPSS 0.5%CVE-2020-25650—A flaw was found in the way the spice-vdagentd daemon handled file transfers from the host system to the virtual machine. Any unprivileged lEPSS 0.5%CVE-2025-14871HIGHAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.5%CVE-2026-56855HIGHPrevent DoS on deadlocked established channel in golang.org/x/crypto/sshEPSS 0.5%CVE-2018-25108HIGHWAGO: Denial of service in 750-8xx controller due to uncontrolled resource consumptionEPSS 0.5%CVE-2023-51309MEDIUMA lack of rate limiting in the 'Email Settings' feature of PHPJabbers Car Park Booking System v3.0 allows attackers to send an excessive amoEPSS 0.5%CVE-2023-51310MEDIUMA lack of rate limiting in the 'Forgot Password', 'Email Settings' feature of PHPJabbers Car Park Booking System v3.0 allows attackers to seEPSS 0.5%CVE-2025-54500MEDIUMHTTP/2 VulnerabilityEPSS 0.5%CVE-2025-32381MEDIUMDenial of Service by abusing xgrammar unbounded cache in memoryEPSS 0.5%CVE-2024-7113HIGHAllocation of Resources Without Limits or Throttling in AVEVA SuiteLink ServerEPSS 0.5%CVE-2020-36949MEDIUMTapinRadio 2.13.7 - Denial of ServiceEPSS 0.5%