Fallos del tipo CWE-770

1861 resultados

Alocação sem limite de recursos

A aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem impor limites, permitindo que um atacante esgote os recursos do sistema. O risco é negação de serviço: a aplicação ou servidor inteiro pode travar quando os recursos acabam.

Ejemplo

Um servidor web aceita requisições sem limitar quantas conexões simultâneas um único usuário pode abrir, ou um upload sem verificar tamanho máximo. Um atacante abre milhões de conexões ou envia arquivos gigantes até a memória/disco encher.

Cómo mitigar

Implemente quotas e limites por usuário/origem (rate limiting, máximo de conexões simultâneas, tamanho máximo de upload). Monitore consumo de recursos e recuse requisições que violem os limites com erro 429 ou similar.

CVE-2026-54716HIGHValhalla: Degenerate exclude_polygons (collinear points, zero area) causes OOM in /sources_to_targetsEPSS 0.5%CVE-2026-30071HIGHAn issue in the RechargePut function of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.EPSS 0.5%CVE-2026-45290HIGHCloudburst Network has DoS in RakNet connection handling due to missing bound checksEPSS 0.5%CVE-2026-30051HIGHAn issue in the CreateUEContextProcedure function (/v1/ue-contexts/{supi}) of free5gc v4.1.0 allows attackers to cause a Denial of Service (EPSS 0.5%CVE-2026-30067HIGHAn issue in the complexQueryFilterSubprocess function in the NRF Discovery service of free5gc v4.0.1 allows attackers to cause a Denial of SEPSS 0.5%CVE-2026-41851MEDIUMSpring Framework Denial of Service via Unbounded Cache in SpELEPSS 0.5%CVE-2026-41007HIGHSpring HATEOAS heap exhaustion through unbounded internal cachingEPSS 0.5%CVE-2026-48702HIGHRekor has an OOM Condition due to Unbounded gzip Decompression in Alpine APK Parsing LogicEPSS 0.5%CVE-2026-21729HIGHLoki detected_fields query limits results in unbounded memory allocationEPSS 0.5%CVE-2026-34826MEDIUMRack: Unbounded Range Count in get_byte_ranges Enables DoSEPSS 0.5%CVE-2026-30060HIGHAn issue in free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) when parsing crafted SUCI data during UE registration.EPSS 0.5%CVE-2025-68148MEDIUMFreshRSS globally denies access to feed via proxy modifying to 429 Retry-AfterEPSS 0.5%CVE-2026-40629HIGHBIG-IP SSL/TLS vulnerabilityEPSS 0.5%CVE-2026-30050HIGHAn issue in the ModifyAMFEventSubscriptionProcedure function (processor/event_exposure.go) of free5gc v4.1.0 allows attackers to cause a DenEPSS 0.5%CVE-2026-44697HIGHKlever-Go MultiDataInterceptor: remote OOM via crafted compressed P2P payloadEPSS 0.5%CVE-2026-81285HIGHWordPress Smush Image Compression and Optimization plugin <= 4.2.0 - Denial of Service Attack vulnerabilityEPSS 0.5%CVE-2026-46702HIGHRussh: Post-decompression SSH packet size was not bounded, allowing remote oversized compressed packetsEPSS 0.5%CVE-2026-30059HIGHAn issue in the NAS decoder component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted Registration RequeEPSS 0.5%CVE-2025-53628MEDIUMcpp-httplib does not limit the length of a lineEPSS 0.5%CVE-2025-30260HIGHQsync CentralEPSS 0.5%