Fallos del tipo CWE-770

1865 resultados

Alocação sem limite de recursos

A aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem impor limites, permitindo que um atacante esgote os recursos do sistema. O risco é negação de serviço: a aplicação ou servidor inteiro pode travar quando os recursos acabam.

Ejemplo

Um servidor web aceita requisições sem limitar quantas conexões simultâneas um único usuário pode abrir, ou um upload sem verificar tamanho máximo. Um atacante abre milhões de conexões ou envia arquivos gigantes até a memória/disco encher.

Cómo mitigar

Implemente quotas e limites por usuário/origem (rate limiting, máximo de conexões simultâneas, tamanho máximo de upload). Monitore consumo de recursos e recuse requisições que violem os limites com erro 429 ou similar.

CVE-2026-77633HIGHCloudreve: Storage-quota TOCTOU race allows quota bypass and storage-based denial of serviceEPSS 0.4%CVE-2026-41078MEDIUMOpenTelemetry dotnet: Potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion pathEPSS 0.4%CVE-2026-41710MEDIUMCache Exhaustion in Stateful Retries leads to Denial of ServiceEPSS 0.4%CVE-2020-36950HIGHLaravel Nova 3.7.0 - 'range' DoSEPSS 0.4%CVE-2026-10600MEDIUMDenial of service via unbounded document content extraction in Mattermost ServerEPSS 0.4%CVE-2025-11044HIGHVulnerability on Automation Runtime my cause DoS ConditionsEPSS 0.4%CVE-2026-92560HIGHApache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication in the AMQP 0-10 decoderEPSS 0.4%CVE-2026-59287MEDIUMSpring for GraphQL WebSocket Client Denial of ServiceEPSS 0.4%CVE-2026-71054MEDIUMVulnerability in Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 7u511. Easily exploitable vulneraEPSS 0.4%CVE-2026-47885HIGHSpring Framework maxPartSize Ignored in PartEventHttpMessageReaderEPSS 0.4%CVE-2025-27157MEDIUMMastodon's rate-limits are missing on `/auth/setup`EPSS 0.4%CVE-2025-64702MEDIUMquic-go HTTP/3 QPACK Header Expansion DoSEPSS 0.4%CVE-2025-33039HIGHQsync CentralEPSS 0.4%CVE-2024-45669MEDIUMIBM Security Verify Information Queue denial of serviceEPSS 0.4%CVE-2025-44006HIGHQsync CentralEPSS 0.4%CVE-2025-33040HIGHQsync CentralEPSS 0.4%CVE-2025-44007HIGHQsync CentralEPSS 0.4%CVE-2026-1662HIGHAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.4%CVE-2026-1725MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.4%CVE-2023-25153MEDIUMcontainerd OCI image importer memory exhaustionEPSS 0.4%