Fallos del tipo CWE-770

1861 resultados

Alocação sem limite de recursos

A aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem impor limites, permitindo que um atacante esgote os recursos do sistema. O risco é negação de serviço: a aplicação ou servidor inteiro pode travar quando os recursos acabam.

Ejemplo

Um servidor web aceita requisições sem limitar quantas conexões simultâneas um único usuário pode abrir, ou um upload sem verificar tamanho máximo. Um atacante abre milhões de conexões ou envia arquivos gigantes até a memória/disco encher.

Cómo mitigar

Implemente quotas e limites por usuário/origem (rate limiting, máximo de conexões simultâneas, tamanho máximo de upload). Monitore consumo de recursos e recuse requisições que violem os limites com erro 429 ou similar.

CVE-2024-57722HIGHlunasvg v3.0.0 was discovered to contain a allocation-size-too-big bug via the component plutovg_surface_create.EPSS 0.5%CVE-2025-71401CRITICALbetter-auth before 1.4.2 basePath Modification DoSEPSS 0.5%CVE-2025-1250MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.5%CVE-2025-7337MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.5%CVE-2025-26480MEDIUMDell PowerScale OneFS, versions 9.5.0.0 through 9.10.0.0, contains an uncontrolled resource consumption vulnerability. An unauthenticated atEPSS 0.5%CVE-2026-34077HIGHReact Router vulnerable to Denial of Service via reflected user input in single-fetchEPSS 0.5%CVE-2025-1257MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.5%CVE-2014-125127HIGHDenial of Service (DoS) vulnerability in mikecao/flightEPSS 0.5%CVE-2025-0639MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.5%CVE-2026-55531MEDIUMPraisonAI: Unauthenticated unbounded session accumulation in the PraisonAI MCP HTTP server (memory exhaustion; session TTL never enforced)EPSS 0.5%CVE-2026-8202MEDIUMPost-authentication CPU utilization DoS via $trim/$ltrim/$rtrim operatorsEPSS 0.5%CVE-2026-48854HIGHUnbounded request body accumulation causes memory exhaustion in elixir-grpc/grpcEPSS 0.5%CVE-2025-36047MEDIUMIBM WebSphere Application Server Liberty denial of serviceEPSS 0.5%CVE-2026-45802MEDIUMFPDI: Memory Exhaustion and Endless Loop in FPDI leads to Denial of ServiceEPSS 0.5%CVE-2026-65650MEDIUMElgg before 7.0.0 does not check image dimensions to prevent denial of service via a large avatar upload.EPSS 0.5%CVE-2021-47959HIGHWordPress Plugin WPGraphQL 1.3.5 Denial of ServiceEPSS 0.5%CVE-2025-59139MEDIUMHono has Body Limit Middleware BypassEPSS 0.4%CVE-2026-62210MEDIUMOpenClaw < 2026.6.1 Denial of Service via Remote Media URLsEPSS 0.4%CVE-2024-23826MEDIUMUploading an image with a specific filename causes a server-side DoS EPSS 0.4%CVE-2026-22773MEDIUMvLLM is vulnerable to DoS in Idefics3 vision models via image payload with ambiguous dimensionsEPSS 0.4%