Fallos del tipo CWE-770
1861 resultadosAlocação sem limite de recursos
A aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem impor limites, permitindo que um atacante esgote os recursos do sistema. O risco é negação de serviço: a aplicação ou servidor inteiro pode travar quando os recursos acabam.
Ejemplo
Um servidor web aceita requisições sem limitar quantas conexões simultâneas um único usuário pode abrir, ou um upload sem verificar tamanho máximo. Um atacante abre milhões de conexões ou envia arquivos gigantes até a memória/disco encher.
Cómo mitigar
Implemente quotas e limites por usuário/origem (rate limiting, máximo de conexões simultâneas, tamanho máximo de upload). Monitore consumo de recursos e recuse requisições que violem os limites com erro 429 ou similar.
CVE-2024-21875MEDIUMDoS attack when broadcasting billboard messagesEPSS 0.5%CVE-2025-53409MEDIUMFile Station 5EPSS 0.5%CVE-2025-53634HIGHChall-Manager's HTTP Gateway have no header check timeout leading to potential slow loris attacksEPSS 0.5%CVE-2025-53410MEDIUMFile Station 5EPSS 0.5%CVE-2025-53413MEDIUMFile Station 5EPSS 0.5%CVE-2025-3111MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.5%CVE-2018-25112HIGHPHOENIX CONTACT: ILC 1x1 ETH Denial of ServiceEPSS 0.5%CVE-2026-26312MEDIUMStalwart Mail Server has Out-of-Memory Denial of Service via Malformed Nested MIME MessagesEPSS 0.5%CVE-2026-15561HIGHUndertow-core: oom via missing limits in chunked trailer in eap's undertowEPSS 0.5%CVE-2025-29770MEDIUMvLLM denial of service via outlines unbounded cache on diskEPSS 0.5%CVE-2025-8916MEDIUMPossible DOS in processing large name constraint structures in PKIXCertPathReveiwerEPSS 0.5%CVE-2025-30261HIGHQsync CentralEPSS 0.5%CVE-2026-84778HIGHWordPress Migrate Guru – Site Migration & Cloning plugin <= 6.65 - Denial of Service Attack vulnerabilityEPSS 0.5%CVE-2025-29890HIGHFile Station 5EPSS 0.5%CVE-2026-30071HIGHAn issue in the RechargePut function of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.EPSS 0.5%CVE-2024-47401MEDIUMDoS via Amplified GraphQL Response in PlaybooksEPSS 0.5%CVE-2025-29900HIGHFile Station 5EPSS 0.5%CVE-2026-30051HIGHAn issue in the CreateUEContextProcedure function (/v1/ue-contexts/{supi}) of free5gc v4.1.0 allows attackers to cause a Denial of Service (EPSS 0.5%CVE-2026-40881MEDIUMZebra: addr/addrv2 Deserialization Resource ExhaustionEPSS 0.5%CVE-2026-46673HIGHRussh: Unchecked CryptoVec allocation and growth handling is reachable from local agent inputs in current russh releases and from remote SSH traffic in historical pre-0.58.0 releasesEPSS 0.5%