Fallos del tipo CWE-770

1866 resultados

Alocação sem limite de recursos

A aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem impor limites, permitindo que um atacante esgote os recursos do sistema. O risco é negação de serviço: a aplicação ou servidor inteiro pode travar quando os recursos acabam.

Ejemplo

Um servidor web aceita requisições sem limitar quantas conexões simultâneas um único usuário pode abrir, ou um upload sem verificar tamanho máximo. Um atacante abre milhões de conexões ou envia arquivos gigantes até a memória/disco encher.

Cómo mitigar

Implemente quotas e limites por usuário/origem (rate limiting, máximo de conexões simultâneas, tamanho máximo de upload). Monitore consumo de recursos e recuse requisições que violem os limites com erro 429 ou similar.

CVE-2024-23979HIGHBIG-IP SSL Client Certificate LDAP and CRLDP Authentication profiles vulnerabilityEPSS 0.3%CVE-2025-59459MEDIUMDenial-of-service (DoS) via resource consumptionEPSS 0.3%CVE-2026-7776HIGHBoundary Workers Vulnerable to Denial of Service During TLS HandshakeEPSS 0.3%CVE-2025-65942LOWVictoriaMetrics Snappy Decoder DoS Vulnerability is Causing OOMEPSS 0.3%CVE-2025-59045HIGHStalwart vulnerable to Memory Exhaustion via CalDAV Event ExpansionEPSS 0.3%CVE-2026-29795MEDIUMstellar-xdr: `StringM::from_str` bypasses max length validationEPSS 0.3%CVE-2026-15055MEDIUMPKCS#8 / PBES2 decryptors honour unbounded KDF cost from inputEPSS 0.3%CVE-2025-14870HIGHAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.3%CVE-2026-6060MEDIUMPossible DoS via SQL BoxEPSS 0.3%CVE-2025-61775MEDIUMVickey's unexpired email confirmation link can be reused to send repeated confirmation emailsEPSS 0.3%CVE-2026-82439CRITICALApache Storm DRPC: Unauthenticated Unbounded Memory Growth in DRPCEPSS 0.3%CVE-2026-45712MEDIUMMailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write)EPSS 0.3%CVE-2026-0897HIGHDenial of Service in Keras via Excessive Memory Allocation in HDF5 MetadataEPSS 0.3%CVE-2025-59778HIGHVELOS partition container network vulnerabilityEPSS 0.3%CVE-2024-4781MEDIUMA denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to cEPSS 0.3%CVE-2025-49000LOWInvenTree has uncontrolled memory allocation via built-in label-sheet pluginEPSS 0.3%CVE-2026-27932HIGHjoserfc PBES2 p2c Unbounded Iteration Count enables Denial of Service (DoS)EPSS 0.3%CVE-2025-55199MEDIUMHelm Charts with Specific JSON Schema Values Can Cause Memory ExhaustionEPSS 0.3%CVE-2025-61595HIGHMANTRA tx gas limit is not enforced in send hooksEPSS 0.3%CVE-2025-66487LOWMultiple vulnerabilities have been addressed in IBM Aspera SharesEPSS 0.3%