Fallos del tipo CWE-770

1861 resultados

Alocação sem limite de recursos

A aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem impor limites, permitindo que um atacante esgote os recursos do sistema. O risco é negação de serviço: a aplicação ou servidor inteiro pode travar quando os recursos acabam.

Ejemplo

Um servidor web aceita requisições sem limitar quantas conexões simultâneas um único usuário pode abrir, ou um upload sem verificar tamanho máximo. Um atacante abre milhões de conexões ou envia arquivos gigantes até a memória/disco encher.

Cómo mitigar

Implemente quotas e limites por usuário/origem (rate limiting, máximo de conexões simultâneas, tamanho máximo de upload). Monitore consumo de recursos e recuse requisições que violem os limites com erro 429 ou similar.

CVE-2026-7768HIGH@fastify/accepts-serializer vulnerable to Denial of Service via Unbounded Accept Header Cache GrowthEPSS 0.5%CVE-2026-54465MEDIUMwebsocket-driver: Memory exhaustion in HTTP header parserEPSS 0.5%CVE-2026-73062HIGHScriban 3.0.0 through 7.2.0 Denial of Service via Array MultiplicationEPSS 0.5%CVE-2026-9675HIGHundici WebSocket client vulnerable to denial of service via cumulative fragment bypassEPSS 0.5%CVE-2026-24514MEDIUMingress-nginx Admission Controller denial of serviceEPSS 0.5%CVE-2026-44453HIGHh2o is vulnerable to musl libc stack overflowEPSS 0.5%CVE-2026-52880HIGHKlever-Go: REST API slow-header connection exhaustion via Gin Engine.RunEPSS 0.5%CVE-2026-48804HIGHpython-socketio: Binary attachment accumulation can cause denial of serviceEPSS 0.5%CVE-2026-44433MEDIUMQuicly is vulnerable to memory exhaustionEPSS 0.5%CVE-2026-40898MEDIUMquic-go: HTTP/3 QPACK Trailer Expansion Memory ExhaustionEPSS 0.5%CVE-2026-57080HIGHNet::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustion via an uncapped peer-wire message-length prefixEPSS 0.5%CVE-2026-74788HIGHScriban before 7.0.0 Denial of Service via string.pad_left/pad_rightEPSS 0.5%CVE-2026-91990HIGHTornado before 6.5.8 Memory Amplification DoS via multipartEPSS 0.5%CVE-2026-37736HIGHAn issue in the JsonSanitizer.sanitize() component of OWASP json-sanitizer v1.2.3 allows attackers to cause a Denial of Service (DoS) via a EPSS 0.5%CVE-2026-26445HIGHstomper 5e2741e is vulnerable to Denial of Service. A malicious client can send partial STOMP frames and keep the TCP connections open, whicEPSS 0.5%CVE-2026-54463MEDIUMwebsocket-driver: Memory exhaustion via abuse of protocol length headersEPSS 0.5%CVE-2026-52879HIGHKlever-Go: Unbounded goroutine spawn on direct-message ingress enables peer-driven DoSEPSS 0.5%CVE-2025-57710LOWQsync CentralEPSS 0.5%CVE-2025-1477MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.5%CVE-2025-58471LOWQsync CentralEPSS 0.5%