Fallos del tipo CWE-770
1865 resultadosAlocação sem limite de recursos
A aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem impor limites, permitindo que um atacante esgote os recursos do sistema. O risco é negação de serviço: a aplicação ou servidor inteiro pode travar quando os recursos acabam.
Ejemplo
Um servidor web aceita requisições sem limitar quantas conexões simultâneas um único usuário pode abrir, ou um upload sem verificar tamanho máximo. Um atacante abre milhões de conexões ou envia arquivos gigantes até a memória/disco encher.
Cómo mitigar
Implemente quotas e limites por usuário/origem (rate limiting, máximo de conexões simultâneas, tamanho máximo de upload). Monitore consumo de recursos e recuse requisições que violem os limites com erro 429 ou similar.
CVE-2025-9368HIGH432ES-IG3 Series A Denial-of-Service VulnerabilityEPSS 0.4%CVE-2026-18362MEDIUMDFIR-IRIS Missing Brute Force Protection in User AuthenticationEPSS 0.4%CVE-2026-56255MEDIUMCapgo - Denial of Service via Unlimited Demo App CreationEPSS 0.4%CVE-2024-52973MEDIUMKibana allocation of resources without limits or throttling leads to crashEPSS 0.4%CVE-2025-3050MEDIUMIBM Db2 denial of serviceEPSS 0.4%CVE-2026-75841MEDIUMArcadeDB before 26.8.1 Denial of Service via range()EPSS 0.4%CVE-2026-82309MEDIUMRobots::Validate versions from 0.3.2 before 0.3.11 for Perl allow unbounded outbound DNS queries per validation via a forward-confirmation loop that does not bound the names it queriesEPSS 0.4%CVE-2025-36387MEDIUMIBM Db2 Denial of ServiceEPSS 0.4%CVE-2025-3279MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.4%CVE-2025-1000MEDIUMIBM Db2 denial of serviceEPSS 0.4%CVE-2025-4225MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.4%CVE-2026-100600MEDIUMClawHub before 8c2de6c506 Quota Exhaustion via Anonymous APIEPSS 0.4%CVE-2025-54884HIGHVision UI security-kit.js: Potential Uncontrolled Resource Allocation VulnerabilityEPSS 0.4%CVE-2025-2403HIGHA denial-of-service vulnerability due to improper prioritization of network traffic over protection mechanism exists in Relion 670/650 and SEPSS 0.4%CVE-2025-48053HIGHDiscourse vulnerable to DoS via large URL payload in PM to a botEPSS 0.4%CVE-2026-48045MEDIUMZeroconf: Unbounded TC-deferred queue allows LAN-local memory exhaustion via spoofed-source floodEPSS 0.4%CVE-2021-22532HIGHPossible NLDAP Denial of Service attack VulnerabilityEPSS 0.4%CVE-2025-11832CRITICALAPIs Lack Rate LimitingEPSS 0.4%CVE-2023-38543HIGHA vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attackerEPSS 0.4%CVE-2025-62426MEDIUMvLLM vulnerable to DoS via large Chat Completion or Tokenization requests with specially crafted `chat_template_kwargs`EPSS 0.4%