Fallos del tipo CWE-770

1861 resultados

Alocação sem limite de recursos

A aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem impor limites, permitindo que um atacante esgote os recursos do sistema. O risco é negação de serviço: a aplicação ou servidor inteiro pode travar quando os recursos acabam.

Ejemplo

Um servidor web aceita requisições sem limitar quantas conexões simultâneas um único usuário pode abrir, ou um upload sem verificar tamanho máximo. Um atacante abre milhões de conexões ou envia arquivos gigantes até a memória/disco encher.

Cómo mitigar

Implemente quotas e limites por usuário/origem (rate limiting, máximo de conexões simultâneas, tamanho máximo de upload). Monitore consumo de recursos e recuse requisições que violem os limites com erro 429 ou similar.

CVE-2026-80179MEDIUMJwcrypto: jwcrypto: denial of service via malformed jwe tokensEPSS 0.4%CVE-2020-37039MEDIUMFrigate 2.02 - Denial Of ServiceEPSS 0.4%CVE-2026-58488MEDIUMHedgeDoc: Rate-limit bypass via CF-Connecting-IP header spoofingEPSS 0.4%CVE-2025-1677MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.4%CVE-2026-85219LOWDenial-of-Service in the OpenCanary Redis serviceEPSS 0.4%CVE-2026-46553LOWNocoDB: Attachment Size Limit Bypass via Upload-by-URLEPSS 0.4%CVE-2026-85220LOWDenial-of-Service in the Thinkst Canary Redis serviceEPSS 0.4%CVE-2026-48510MEDIUMMessagePack-CSharp: LZ4 decompression allocates from unbounded declared output lengthsEPSS 0.4%CVE-2026-48514MEDIUMMessagePack-CSharp: Unity unsafe blit formatter allocates from unbounded byte lengthEPSS 0.4%CVE-2025-55102HIGHA denial-of-service vulnerability exists in the NetX IPv6 component functionality of Eclipse ThreadX NetX Duo. A specially crafted network pEPSS 0.4%CVE-2026-48515MEDIUMMessagePack-CSharp: Multi-dimensional array formatters allocate from unchecked dimensionsEPSS 0.4%CVE-2026-40395MEDIUMVarnish Enterprise before 6.0.16r12 allows a "workspace overflow" denial of service (daemon panic) for shared VCL. The headerplus.write_req0EPSS 0.4%CVE-2021-47875MEDIUMGeoGebra CAS Calculator 6.0.631.0 - Denial of ServiceEPSS 0.4%CVE-2024-51461MEDIUMIBM QRadar WinCollect Agent denial of serviceEPSS 0.4%CVE-2026-23826HIGHUnauthenticated Denial of Service in AOS-8 Network Management ServiceEPSS 0.4%CVE-2025-22484HIGHFile Station 5EPSS 0.4%CVE-2025-66473HIGHXWiki's REST APIs don't enforce any limits, leading to unavailability and OOM in large wikisEPSS 0.4%CVE-2025-5253MEDIUMDoS in Kron Technologies' Kron PAMEPSS 0.4%CVE-2026-82054HIGHUncontrolled Resource Consumption in MongoDB Server JSON Pointer Parser Leads to Denial of ServiceEPSS 0.4%CVE-2025-3922MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.4%