Fallos del tipo CWE-770
1861 resultadosAlocação sem limite de recursos
A aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem impor limites, permitindo que um atacante esgote os recursos do sistema. O risco é negação de serviço: a aplicação ou servidor inteiro pode travar quando os recursos acabam.
Ejemplo
Um servidor web aceita requisições sem limitar quantas conexões simultâneas um único usuário pode abrir, ou um upload sem verificar tamanho máximo. Um atacante abre milhões de conexões ou envia arquivos gigantes até a memória/disco encher.
Cómo mitigar
Implemente quotas e limites por usuário/origem (rate limiting, máximo de conexões simultâneas, tamanho máximo de upload). Monitore consumo de recursos e recuse requisições que violem os limites com erro 429 ou similar.
CVE-2026-42034MEDIUMAxios: HTTP adapter streamed uploads bypass maxBodyLength when maxRedirects: 0EPSS 0.5%CVE-2026-42036MEDIUMAxios: HTTP adapter streamed responses bypass maxContentLengthEPSS 0.5%CVE-2022-3273LOWAllocation of Resources Without Limits or Throttling in ikus060/rdiffwebEPSS 0.5%CVE-2024-4311MEDIUMLack of login attempt rate-limiting in zenml-io/zenmlEPSS 0.5%CVE-2026-15588MEDIUMGdbusserver: glib2: gdbusserver pre-authentication dos via unbounded sasl line bufferingEPSS 0.5%CVE-2026-0531MEDIUMAllocation of Resources Without Limits or Throttling in Kibana FleetEPSS 0.5%CVE-2026-74786HIGHScriban before 7.0.0 Denial of Service via Unbounded Template OutputEPSS 0.5%CVE-2026-54894MEDIUMAtom-table exhaustion denial of service in Guardian via unbounded atom creation from binary keysEPSS 0.5%CVE-2026-91987HIGHatomic-agents-stack before 1.1.0 Cost Guardrail Bypass via Unknown ModelEPSS 0.5%CVE-2026-55733MEDIUMAtom-table exhaustion denial of service in Guardian permissions AtomEncoding via unbounded atom creationEPSS 0.5%CVE-2026-56150MEDIUMAllocation of Resources Without Limits or Throttling in Fleet Server Leading to Denial of ServiceEPSS 0.5%CVE-2026-55734MEDIUMguardian atom exhaustion in Guardian.Permissions.encode_permissions!/1EPSS 0.5%CVE-2022-48357—Some products have the double fetch vulnerability. Successful exploitation of this vulnerability may cause denial of service (DoS) attacks tEPSS 0.5%CVE-2023-30443MEDIUMIBM Db2 denial of serviceEPSS 0.5%CVE-2026-49087MEDIUMAllocation of Resources Without Limits or Throttling in Kibana Leading to Denial of ServiceEPSS 0.5%CVE-2026-49089MEDIUMAllocation of Resources Without Limits or Throttling in Kibana Leading to Denial of ServiceEPSS 0.5%CVE-2026-78586MEDIUMAllocation of Resources Without Limits or Throttling in Kibana Leading to Denial of ServiceEPSS 0.5%CVE-2026-29612MEDIUMOpenClaw < 2026.2.14 - Denial of Service via Large Base64 Media File DecodingEPSS 0.5%CVE-2025-64508HIGHBugsink vulnerable to unauthenticated remote DoS via crafted Brotli inputEPSS 0.5%CVE-2024-31669HIGHrizin before Release v0.6.3 is vulnerable to Uncontrolled Resource Consumption via bin_pe_parse_imports, Pe_r_bin_pe_parse_var, and estimateEPSS 0.5%