Fallos del tipo CWE-770
1851 resultadosAlocação sem limite de recursos
A aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem impor limites, permitindo que um atacante esgote os recursos do sistema. O risco é negação de serviço: a aplicação ou servidor inteiro pode travar quando os recursos acabam.
Ejemplo
Um servidor web aceita requisições sem limitar quantas conexões simultâneas um único usuário pode abrir, ou um upload sem verificar tamanho máximo. Um atacante abre milhões de conexões ou envia arquivos gigantes até a memória/disco encher.
Cómo mitigar
Implemente quotas e limites por usuário/origem (rate limiting, máximo de conexões simultâneas, tamanho máximo de upload). Monitore consumo de recursos e recuse requisições que violem os limites com erro 429 ou similar.
CVE-2024-23185HIGHVery large headers can cause resource exhaustion when parsing message. The message-parser normally reads reasonably sized chunks of the messEPSS 1.3%CVE-2025-21490MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.40 and prior, 8EPSS 1.3%CVE-2021-1350MEDIUMCisco Umbrella Dashboard Packet Flood VulnerabilityEPSS 1.3%CVE-2021-29511MEDIUMMemory over-allocation in evm crateEPSS 1.3%CVE-2024-27268MEDIUMIBM WebSphere Application Server Liberty denial of serviceEPSS 1.3%CVE-2025-21504MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.39 aEPSS 1.3%CVE-2022-20757HIGHCisco Firepower Threat Defense Software Denial of Service VulnerabilityEPSS 1.2%CVE-2023-0121MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 1.2%CVE-2023-6563HIGHKeycloak: offline session token dosEPSS 1.2%CVE-2023-29779HIGHSengled Dimmer Switch V0.0.9 contains a denial of service (DOS) vulnerability, which allows a remote attacker to send malicious Zigbee messaEPSS 1.2%CVE-2022-34357MEDIUMIBM Cognos Analytics Mobile Server denial of serviceEPSS 1.2%CVE-2026-57099HIGHASP.NET Core Denial of Service VulnerabilityEPSS 1.2%CVE-2026-33871HIGHNetty HTTP/2 CONTINUATION Frame Flood DoS via Zero-Byte Frame BypassEPSS 1.2%CVE-2024-23837HIGHLibHTP unbounded folded header handling leads to denial serviceEPSS 1.2%CVE-2025-47950HIGHCoreDNS Vulnerable to DoQ Memory Exhaustion via Stream AmplificationEPSS 1.2%CVE-2018-10908MEDIUMIt was found that vdsm before version 4.20.37 invokes qemu-img on untrusted inputs without limiting resources. By uploading a specially crafEPSS 1.2%CVE-2023-38492MEDIUMKirby vulnerable to denial of service from unlimited password lengthsEPSS 1.2%CVE-2024-1765MEDIUMUnlimited resource allocation by QUIC CRYPTO frames flooding in quicheEPSS 1.2%CVE-2026-49787HIGHHTTP.sys Denial of Service VulnerabilityEPSS 1.2%CVE-2026-45646HIGHOData for ASP.NET and ASP.NET Core Denial of Service VulnerabilityEPSS 1.2%