Fallos del tipo CWE-770
1861 resultadosAlocação sem limite de recursos
A aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem impor limites, permitindo que um atacante esgote os recursos do sistema. O risco é negação de serviço: a aplicação ou servidor inteiro pode travar quando os recursos acabam.
Ejemplo
Um servidor web aceita requisições sem limitar quantas conexões simultâneas um único usuário pode abrir, ou um upload sem verificar tamanho máximo. Um atacante abre milhões de conexões ou envia arquivos gigantes até a memória/disco encher.
Cómo mitigar
Implemente quotas e limites por usuário/origem (rate limiting, máximo de conexões simultâneas, tamanho máximo de upload). Monitore consumo de recursos e recuse requisições que violem os limites com erro 429 ou similar.
CVE-2026-72674MEDIUMAllocation of Resources Without Limits or Throttling in Kibana Leading to Denial of ServiceEPSS 0.4%CVE-2026-28383MEDIUMGrafana plugin resources can lead to unbounded memory allocationEPSS 0.4%CVE-2026-13076HIGHAggregation Framework Memory Exhaustion Leading to Process TerminationEPSS 0.4%CVE-2026-72653MEDIUMAllocation of Resources Without Limits or Throttling in Kibana Leading to Denial of ServiceEPSS 0.4%CVE-2026-72682MEDIUMAllocation of Resources Without Limits or Throttling in Kibana Leading to Denial of ServiceEPSS 0.4%CVE-2020-37038MEDIUMCode Blocks 20.03 - Denial Of ServiceEPSS 0.4%CVE-2026-92915MEDIUMWWBN AVideo userVerifyEmail.php Unauthenticated Access ControlEPSS 0.4%CVE-2025-36504HIGHBIG-IP HTTP/2 vulnerabilityEPSS 0.4%CVE-2025-32393HIGHAutoGPT has a DoS vulnerability in ReadRSSFeedBlockEPSS 0.4%CVE-2026-67353MEDIUMguzzlehttp/guzzle before 7.15.1 Unbounded Cookie Denial of ServiceEPSS 0.4%CVE-2026-48504MEDIUMOpenTelemetry Rust: Unbounded memory allocation in W3C Baggage propagationEPSS 0.4%CVE-2026-10832MEDIUMOrg.wildfly.security/wildfly-elytron-asn1: unbounded memory allocation in wildfly elytron asn.1 derdecoder via crafted der payloadEPSS 0.4%CVE-2025-13436MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.4%CVE-2025-70069HIGHAn issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXConverter.cpp and ConvertMeshMultiMaterial() metEPSS 0.4%CVE-2025-8099HIGHAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.4%CVE-2019-25342HIGHCentova Cast 3.2.12 - Denial of ServiceEPSS 0.4%CVE-2022-50799HIGHFetch Softworks Fetch FTP Client 5.8.2 Remote CPU Consumption Denial of ServiceEPSS 0.4%CVE-2026-44500MEDIUMZEBRA: Allocation Amplification in Inbound Network DeserializersEPSS 0.4%CVE-2025-52867MEDIUMQsync CentralEPSS 0.4%CVE-2025-1478MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.4%