Fallos del tipo CWE-770
1861 resultadosAlocação sem limite de recursos
A aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem impor limites, permitindo que um atacante esgote os recursos do sistema. O risco é negação de serviço: a aplicação ou servidor inteiro pode travar quando os recursos acabam.
Ejemplo
Um servidor web aceita requisições sem limitar quantas conexões simultâneas um único usuário pode abrir, ou um upload sem verificar tamanho máximo. Um atacante abre milhões de conexões ou envia arquivos gigantes até a memória/disco encher.
Cómo mitigar
Implemente quotas e limites por usuário/origem (rate limiting, máximo de conexões simultâneas, tamanho máximo de upload). Monitore consumo de recursos e recuse requisições que violem os limites com erro 429 ou similar.
CVE-2025-57711LOWQsync CentralEPSS 0.5%CVE-2026-40902HIGHPhpSpreadsheet: CPU Denial of Service via Unbounded Row Number in XLSX Row DimensionsEPSS 0.5%CVE-2026-45352MEDIUMcpp-httplib DoS: Negative chunk-size in chunked Transfer-EncodingEPSS 0.5%CVE-2026-41324HIGHbasic-ftp vulnerable to denial of service via unbounded memory consumption in Client.list()EPSS 0.5%CVE-2026-42582HIGHNetty: HTTP/3 QPACK literal unbounded allocationEPSS 0.5%CVE-2026-42583HIGHNetty: Lz4FrameDecoder resource exhaustionEPSS 0.5%CVE-2026-35405HIGHlibp2p-rendezvous: Unlimited namespace registrations per peer enables OOM DoS on rendezvous serversEPSS 0.5%CVE-2026-40863HIGHPhpSpreadsheet: CPU Denial of Service via Unbounded Row Index in SpreadsheetML XML ReaderEPSS 0.5%CVE-2025-53032MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 9.0.0-9.EPSS 0.5%CVE-2023-5963LOWAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.5%CVE-2025-53411LOWFile Station 5EPSS 0.5%CVE-2025-68151MEDIUMCoreDNS gRPC/HTTPS/HTTP3 servers lack resource limits, enabling DoS via unbounded connections and oversized messagesEPSS 0.5%CVE-2026-80225MEDIUMPossible degradation of service from continuous queries on the same TCP/DoT connectionEPSS 0.5%CVE-2026-85501MEDIUMRetrap: Novel Vulnerabilities to launch Algorithmic Complexity Attacks on DNSSECEPSS 0.5%CVE-2025-41694MEDIUMAuthenticated Denial-of-Service via WebshellEPSS 0.5%CVE-2026-35526HIGHStrawberry GraphQL affected by a Denial of Service via unbounded WebSocket subscriptionsEPSS 0.5%CVE-2026-26061HIGHFleet's unbounded request body read allows remote Denial of ServiceEPSS 0.5%CVE-2021-47713HIGHHasura GraphQL 1.3.3 Denial of Service via Malicious GraphQL QueryEPSS 0.5%CVE-2024-7734MEDIUMPhoenix Contact: Multiple mGuard devices are vulnerable to a drain of open file descriptors.EPSS 0.5%CVE-2026-54283HIGHStarlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoSEPSS 0.5%