Fallos del tipo CWE-770

1861 resultados

Alocação sem limite de recursos

A aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem impor limites, permitindo que um atacante esgote os recursos do sistema. O risco é negação de serviço: a aplicação ou servidor inteiro pode travar quando os recursos acabam.

Ejemplo

Um servidor web aceita requisições sem limitar quantas conexões simultâneas um único usuário pode abrir, ou um upload sem verificar tamanho máximo. Um atacante abre milhões de conexões ou envia arquivos gigantes até a memória/disco encher.

Cómo mitigar

Implemente quotas e limites por usuário/origem (rate limiting, máximo de conexões simultâneas, tamanho máximo de upload). Monitore consumo de recursos e recuse requisições que violem os limites com erro 429 ou similar.

CVE-2025-1516MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.4%CVE-2025-7449MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.4%CVE-2021-33011—All versions of the afffected TOYOPUC-PC10 Series,TOYOPUC-Plus Series,TOYOPUC-PC3J/PC2J Series, TOYOPUC-Nano Series products may not be ableEPSS 0.4%CVE-2026-34052MEDIUMLTI JupyterHub Authenticator: Unbounded Memory Growth via Nonce Storage (Denial of Service)EPSS 0.4%CVE-2026-73198HIGHIpa: freeipa: unauthenticated dos in `/ipa/i18n_messages` via unbounded request body readEPSS 0.4%CVE-2025-68388MEDIUMAllocation of resources without limits or throttling (CWE-770) allows an unauthenticated remote attacker to cause excessive allocation (CAPEEPSS 0.4%CVE-2026-84890MEDIUMundici vulnerable to Denial of Service via unbounded decompression of compressed responsesEPSS 0.4%CVE-2025-13165HIGHDigiwin|EasyFlow GP - Denial of serviceEPSS 0.4%CVE-2026-12590LOWbody-parser vulnerable to denial of service when invalid limit value silently disables size enforcementEPSS 0.4%CVE-2026-73197HIGHIpa: freeipa: unauthenticated dos in `/ipa/migration/migration.py` via unbounded request body readEPSS 0.4%CVE-2025-58058MEDIUMgithub.com/ulikunitz/xz leaks memory when decoding a corrupted multiple LZMA archivesEPSS 0.4%CVE-2026-46551MEDIUMNocoDB: Missing File Size Enforcement in Upload-by-URL Allows Denial of Service via Disk ExhaustionEPSS 0.4%CVE-2026-53522MEDIUMNezha Monitoring: Unbounded WebSocket Streams — Resource Exhaustion DoSEPSS 0.4%CVE-2026-36499MEDIUMA missing upper-bound check in the udpif_set_threads() function of Open vSwitch v3.6.90 allows an attacker with OVSDB write access to requesEPSS 0.4%CVE-2026-47013MEDIUMVulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u491. Easily exploitable vEPSS 0.4%CVE-2025-65015CRITICALjoserfc has Possible Uncontrolled Resource Consumption Vulnerability Triggered by Logging Arbitrarily Large JWT Token PayloadsEPSS 0.4%CVE-2026-40115MEDIUMPraisonAI has an Unrestricted Upload Size in WSGI Recipe Registry Server Enables Memory Exhaustion DoSEPSS 0.4%CVE-2026-58107MEDIUMAuthenticated Remote Denial of Service via Unbounded zlib Decompression in massStoreRunEPSS 0.4%CVE-2026-92063MEDIUMDenial-of-service in the Audio/Video componentEPSS 0.4%CVE-2026-57224MEDIUMSuricata dhcp: unbounded transactions in unidirectional traffic can lead to resource exhaustionEPSS 0.4%