Fallos del tipo CWE-770
1864 resultadosAlocação sem limite de recursos
A aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem impor limites, permitindo que um atacante esgote os recursos do sistema. O risco é negação de serviço: a aplicação ou servidor inteiro pode travar quando os recursos acabam.
Ejemplo
Um servidor web aceita requisições sem limitar quantas conexões simultâneas um único usuário pode abrir, ou um upload sem verificar tamanho máximo. Um atacante abre milhões de conexões ou envia arquivos gigantes até a memória/disco encher.
Cómo mitigar
Implemente quotas e limites por usuário/origem (rate limiting, máximo de conexões simultâneas, tamanho máximo de upload). Monitore consumo de recursos e recuse requisições que violem os limites com erro 429 ou similar.
CVE-2025-14466MEDIUMGüralp Systems Fortimus Series, Minimus Series, and Certimus Series have an Allocation of Resources Without Limits or Throttling vulnerabilityEPSS 0.4%CVE-2026-48082LOWOpenReception's bootstrap challenge proof-of-work difficulty hardcoded to 16 bits, which enables abuse rate amplificationEPSS 0.4%CVE-2025-0915MEDIUMIBM Db2 denial of serviceEPSS 0.4%CVE-2026-58661MEDIUMn8n - Disk Space Exhaustion via Data-Table File Upload EndpointEPSS 0.4%CVE-2025-48038MEDIUMUnverified File Handles can Cause Excessive Use of System ResourcesEPSS 0.4%CVE-2025-12576MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.4%CVE-2025-11974MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.4%CVE-2025-48039MEDIUMUnverified Paths can Cause Excessive Use of System ResourcesEPSS 0.4%CVE-2025-13690MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.4%CVE-2025-48041HIGHSSH_FXP_OPENDIR may Lead to Exhaustion of File HandlesEPSS 0.4%CVE-2025-46556MEDIUMMantisBT is Vulnerable to Denial-of-Service (DoS) attack via Excessive Note LengthEPSS 0.4%CVE-2023-33656MEDIUMA memory leak vulnerability exists in NanoMQ 0.17.2. The vulnerability is located in the file message.c. An attacker could exploit this vulnEPSS 0.4%CVE-2024-38316MEDIUMIBM Aspera Shares Denial of ServiceEPSS 0.4%CVE-2020-37134MEDIUMUltraVNC Viewer 1.2.4.0 - 'VNCServer' Denial of ServiceEPSS 0.4%CVE-2026-66761MEDIUMMultiple vulnerabilities in SAP Business AI Platform (Approuter)EPSS 0.4%CVE-2024-52913MEDIUMIn Bitcoin Core before 0.21.0, an attacker could prevent a node from seeing a specific unconfirmed transaction, because transaction re-requeEPSS 0.4%CVE-2024-36378MEDIUMIn JetBrains TeamCity before 2024.03.2 server was susceptible to DoS attacks with incorrect auth tokensEPSS 0.4%CVE-2024-50955HIGHAn issue in how XINJE XD5E-24R and XL5E-16T v3.5.3b handles TCP protocol messages allows attackers to cause a Denial of Service (DoS) via a EPSS 0.4%CVE-2025-32394MEDIUMAutoGPT: There is a DoS vulnerability in AITextSummarizerBlockEPSS 0.4%CVE-2025-32423MEDIUMAutoGPT: There is a DoS vulnerability in ExtractTextInformationBlockEPSS 0.4%