Fallos del tipo CWE-770

1861 resultados

Alocação sem limite de recursos

A aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem impor limites, permitindo que um atacante esgote os recursos do sistema. O risco é negação de serviço: a aplicação ou servidor inteiro pode travar quando os recursos acabam.

Ejemplo

Um servidor web aceita requisições sem limitar quantas conexões simultâneas um único usuário pode abrir, ou um upload sem verificar tamanho máximo. Um atacante abre milhões de conexões ou envia arquivos gigantes até a memória/disco encher.

Cómo mitigar

Implemente quotas e limites por usuário/origem (rate limiting, máximo de conexões simultâneas, tamanho máximo de upload). Monitore consumo de recursos e recuse requisições que violem os limites com erro 429 ou similar.

CVE-2025-32386MEDIUMHelm Allows A Specially Crafted Chart Archive To Cause Out Of Memory TerminationEPSS 0.4%CVE-2026-22773MEDIUMvLLM is vulnerable to DoS in Idefics3 vision models via image payload with ambiguous dimensionsEPSS 0.4%CVE-2023-4138MEDIUMAllocation of Resources Without Limits or Throttling in ikus060/rdiffwebEPSS 0.4%CVE-2026-28452MEDIUMOpenClaw < 2026.2.14 - Denial of Service via Unguarded Archive Extraction in extractArchiveEPSS 0.4%CVE-2026-44679MEDIUMTuist: Forgot password flow lacks throttling for reset email deliveryEPSS 0.4%CVE-2026-8488MEDIUMAllocation of resources without limits or throttling vulnerability in Progress Software MOVEit AutomationEPSS 0.4%CVE-2026-74784HIGHScriban before 7.2.0 Denial of Service via array.insert_atEPSS 0.4%CVE-2026-24006HIGHSeroval affected by Denial of Service via Deeply Nested ObjectsEPSS 0.4%CVE-2026-54464MEDIUMwebsocket-driver: Resource limit bypass via message compressionEPSS 0.4%CVE-2026-23957HIGHseroval is vulnerable to Denial of Service via array serializationEPSS 0.4%CVE-2026-54490MEDIUMwebsocket-driver: Resource limit bypass via message compressionEPSS 0.4%CVE-2026-32941MEDIUMSliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard TransportsEPSS 0.4%CVE-2026-33743MEDIUMIncus vulnerable to denial of source through crafted bucket backup fileEPSS 0.4%CVE-2026-54024MEDIUMLibreChat: Incomplete Fix for CVE-2024-11171 — Conversation Import Multer Instance Missing File Size LimitsEPSS 0.4%CVE-2026-33541MEDIUMTSPortal's Uncontrolled User Creation via Validation Side Effects Leads to Potential Denial of ServiceEPSS 0.4%CVE-2026-33438MEDIUMStirling-PDF vulnerable to DoS via add-watermarkEPSS 0.4%CVE-2026-13074MEDIUMAwaitable Hello Command in Exhaust Mode Unthrottled Response Loop Leading to Denial of ServiceEPSS 0.4%CVE-2026-54448MEDIUMTrivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parserEPSS 0.4%CVE-2026-33621MEDIUMPinchTab: Unapplied Rate Limiting Middleware Allows Unbounded Brute-Force of API TokenEPSS 0.4%CVE-2025-3221HIGHIBM InfoSphere Information Server denial of serviceEPSS 0.4%