Fallos del tipo CWE-770

1861 resultados

Alocação sem limite de recursos

A aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem impor limites, permitindo que um atacante esgote os recursos do sistema. O risco é negação de serviço: a aplicação ou servidor inteiro pode travar quando os recursos acabam.

Ejemplo

Um servidor web aceita requisições sem limitar quantas conexões simultâneas um único usuário pode abrir, ou um upload sem verificar tamanho máximo. Um atacante abre milhões de conexões ou envia arquivos gigantes até a memória/disco encher.

Cómo mitigar

Implemente quotas e limites por usuário/origem (rate limiting, máximo de conexões simultâneas, tamanho máximo de upload). Monitore consumo de recursos e recuse requisições que violem os limites com erro 429 ou similar.

CVE-2026-61541MEDIUMZapros has an Unbounded Content-Encoding decompression chain that allows denial of serviceEPSS 0.4%CVE-2025-53531HIGHWeGIA allows Uncontrolled Resource Consumption via the fid parameterEPSS 0.4%CVE-2026-75956HIGHJoomla Extension - cmsjunkie.com - DOS vector in pagination parameter handling in J-BusinessDirectory < 6.2.3EPSS 0.4%CVE-2025-53530HIGHWeGIA allows Uncontrolled Resource Consumption via the errorstr parameterEPSS 0.4%CVE-2025-27911MEDIUMAn issue was discovered in Datalust Seq before 2024.3.13545. Expansion of identifiers in message templates can be used to bypass the system EPSS 0.4%CVE-2026-29772MEDIUMAstro: Memory exhaustion DoS due to missing request body size limit in Server IslandsEPSS 0.4%CVE-2026-64773HIGHAn attacker that can reach a container's published TCP port may be able to force the host's forwarding process to buffer an unbounded amountEPSS 0.4%CVE-2026-100656HIGHNetty HttpServerCodec Unbounded Queue Growth via HTTP/1.1 PipeliningEPSS 0.4%CVE-2026-12818CRITICALDVP-12SE Exposure of Sensitive Information VulnerabilityEPSS 0.4%CVE-2026-9140HIGH1718-AENTR/1719-AENTR - Denial of ServiceEPSS 0.4%CVE-2025-54155LOWFile Station 5EPSS 0.4%CVE-2026-73196MEDIUMIpa: freeipa: authenticated dos in `otptoken-add` via unbounded otp key decoding/re-encodingEPSS 0.4%CVE-2025-11362HIGHVersions of the package pdfmake from 0.3.0-beta.1 and before 0.3.0-beta.17 are vulnerable to Allocation of Resources Without Limits or ThrotEPSS 0.4%CVE-2026-77801MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.4%CVE-2026-13260HIGHSecurity vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify AccessEPSS 0.4%CVE-2025-54161LOWFile Station 5EPSS 0.4%CVE-2024-22436MEDIUMA security vulnerability in HPE IceWall Agent products could be exploited remotely to cause a denial of service.EPSS 0.4%CVE-2026-35457HIGHlibp2p-rust has unbounded rendezvous DISCOVER cookies enable remote memory exhaustionEPSS 0.4%CVE-2026-59647MEDIUMCRMF/CMP password-MAC honours unbounded iteration countEPSS 0.4%CVE-2026-58063MEDIUMBCFKS keystore load honours unbounded KDF cost from untrusted fileEPSS 0.4%