Fallos del tipo CWE-770
1865 resultadosAlocação sem limite de recursos
A aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem impor limites, permitindo que um atacante esgote os recursos do sistema. O risco é negação de serviço: a aplicação ou servidor inteiro pode travar quando os recursos acabam.
Ejemplo
Um servidor web aceita requisições sem limitar quantas conexões simultâneas um único usuário pode abrir, ou um upload sem verificar tamanho máximo. Um atacante abre milhões de conexões ou envia arquivos gigantes até a memória/disco encher.
Cómo mitigar
Implemente quotas e limites por usuário/origem (rate limiting, máximo de conexões simultâneas, tamanho máximo de upload). Monitore consumo de recursos e recuse requisições que violem os limites com erro 429 ou similar.
CVE-2024-43708MEDIUMAn allocation of resources without limits or throttling in Kibana can lead to a crash caused by a specially crafted payload to a number of iEPSS 0.4%CVE-2026-24720LOWFile Station 5EPSS 0.4%CVE-2024-52972MEDIUMKibana allocation of resources without limits or throttling leads to crashEPSS 0.4%CVE-2021-0224MEDIUMJunos OS: ANCPD core when hitting maximum-discovery-table-entries limitEPSS 0.4%CVE-2026-1458MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.4%CVE-2026-1456MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.4%CVE-2023-54394MEDIUMPocketMine-MP before 4.18.0-ALPHA2 Bandwidth Amplification via InventoryTransactionPacketEPSS 0.4%CVE-2026-41173MEDIUMUnbounded HTTP response body read in OpenTelemetry.Sampler.AWSEPSS 0.4%CVE-2025-54575MEDIUMImageSharp Triggers an Infinite Loop in its GIF Decoder When Skipping Malformed Comment Extension BlocksEPSS 0.4%CVE-2025-68390MEDIUMElasticsearch Allocation of Resources Without Limits or ThrottlingEPSS 0.4%CVE-2026-78383HIGHApache Tomcat: AJP DoS via missing request bodyEPSS 0.4%CVE-2026-45023MEDIUMAutoGPT: Credit system bypassed via direct block execution in POST /api/blocks/{block_id}/executeEPSS 0.4%CVE-2025-52570LOWLetmein connection limiter allows an arbitrary amount of simultaneous connectionsEPSS 0.4%CVE-2026-41483MEDIUMUnbounded HTTP response body read in OpenTelemetry.Resources.AzureEPSS 0.4%CVE-2026-100660HIGHNetty before 4.2.18.Final QpackEncoder Unbounded Memory RetentionEPSS 0.4%CVE-2024-35969HIGHipv6: fix race condition between ipv6_get_ifaddr and ipv6_del_addrEPSS 0.4%CVE-2021-25671—A vulnerability has been identified in RWG1.M12 (All versions < V1.16.16), RWG1.M12D (All versions < V1.16.16), RWG1.M8 (All versions < V1.1EPSS 0.4%CVE-2026-43678MEDIUMAn unauthenticated remote peer can crash any NIOWebSocket-based server (including Vapor and Hummingbird) with a single 11-byte frame sent afEPSS 0.4%CVE-2022-3456MEDIUMAllocation of Resources Without Limits or Throttling in ikus060/rdiffwebEPSS 0.4%CVE-2021-3527—A flaw was found in the USB redirector device (usb-redir) of QEMU. Small USB packets are combined into a single, large transfer request, to EPSS 0.4%