Fallos del tipo CWE-770

1864 resultados

Alocação sem limite de recursos

A aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem impor limites, permitindo que um atacante esgote os recursos do sistema. O risco é negação de serviço: a aplicação ou servidor inteiro pode travar quando os recursos acabam.

Ejemplo

Um servidor web aceita requisições sem limitar quantas conexões simultâneas um único usuário pode abrir, ou um upload sem verificar tamanho máximo. Um atacante abre milhões de conexões ou envia arquivos gigantes até a memória/disco encher.

Cómo mitigar

Implemente quotas e limites por usuário/origem (rate limiting, máximo de conexões simultâneas, tamanho máximo de upload). Monitore consumo de recursos e recuse requisições que violem os limites com erro 429 ou similar.

CVE-2026-41648MEDIUMIncus: Unbounded YAML Metadata Decode via ParsingEPSS 0.4%CVE-2026-41685MEDIUMIncus: Unbounded binary import disk exhaustionEPSS 0.4%CVE-2024-10468CRITICALPotential race conditions in IndexedDB could have caused memory corruption, leading to a potentially exploitable crash. This vulnerability aEPSS 0.4%CVE-2026-1224MEDIUMTanium addressed an uncontrolled resource consumption vulnerability in Discover.EPSS 0.4%CVE-2024-47509HIGHJunos OS Evolved: Specific low privileged CLI commands and SNMP GET requests can trigger a resource leak #3EPSS 0.4%CVE-2025-32374MEDIUMPossible Denial of Service (DoS) in DNN.PLATFORM registrationEPSS 0.4%CVE-2024-47508HIGHJunos OS Evolved: Specific low privileged CLI commands and SNMP GET requests can trigger a resource leak #2EPSS 0.4%CVE-2024-31880MEDIUMIBM Db2 denial of serviceEPSS 0.4%CVE-2024-47505HIGHJunos OS Evolved: Specific low privileged CLI commands and SNMP GET requests can trigger a resource leak #1EPSS 0.4%CVE-2026-88382HIGHhiredis commit 29ea279 (post-v1.5.0) contains an uncontrolled memory allocation vulnerability in its RESP aggregate parser.EPSS 0.4%CVE-2024-8973MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.4%CVE-2025-68133HIGHEVerest's unlimited connections can lead to DoS through operating system resource exhaustionEPSS 0.4%CVE-2026-47184MEDIUMZeroconf: Unbounded DNS record cache allows LAN-local memory exhaustion via multicast floodEPSS 0.4%CVE-2025-43762MEDIUMLiferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.EPSS 0.4%CVE-2025-58474MEDIUMBIG-IP Advanced WAF and ASM and NGINX App Protect DNS lookup vulnerabilityEPSS 0.4%CVE-2025-8396MEDIUMInsufficiently specific bounds checking on authorization header could lead to denial of service in the Temporal server on all platforms due EPSS 0.4%CVE-2025-66560MEDIUMQuarkus REST has potential worker thread starvation when HTTP connection is closed while waiting to writeEPSS 0.4%CVE-2025-54572MEDIUMRuby SAML DOS vulnerability with large SAML responseEPSS 0.4%CVE-2025-14466MEDIUMGüralp Systems Fortimus Series, Minimus Series, and Certimus Series have an Allocation of Resources Without Limits or Throttling vulnerabilityEPSS 0.4%CVE-2025-2614MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.4%