Fallos del tipo CWE-770
1866 resultadosAlocação sem limite de recursos
A aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem impor limites, permitindo que um atacante esgote os recursos do sistema. O risco é negação de serviço: a aplicação ou servidor inteiro pode travar quando os recursos acabam.
Ejemplo
Um servidor web aceita requisições sem limitar quantas conexões simultâneas um único usuário pode abrir, ou um upload sem verificar tamanho máximo. Um atacante abre milhões de conexões ou envia arquivos gigantes até a memória/disco encher.
Cómo mitigar
Implemente quotas e limites por usuário/origem (rate limiting, máximo de conexões simultâneas, tamanho máximo de upload). Monitore consumo de recursos e recuse requisições que violem os limites com erro 429 ou similar.
CVE-2026-16971MEDIUMDFIR-IRIS Missing Brute Force Protection in OTP ValidationEPSS 0.3%CVE-2021-28715MEDIUMGuest can force Linux netback driver to hog large amounts of kernel memory T[his CNA information record relates to multiple CVEs; the text eEPSS 0.3%CVE-2025-47208MEDIUMQTS, QuTS heroEPSS 0.3%CVE-2025-15474MEDIUMAuntyFey Smart Combination Lock BLE Connection Flood DoSEPSS 0.3%CVE-2023-31914MEDIUMJerryscript 3.0 (commit 05dbbd1) was discovered to contain out-of-memory issue in malloc.EPSS 0.3%CVE-2025-29606MEDIUMpy-libp2p before 0.2.3 allows a peer to cause a denial of service (resource consumption) via a large RSA key.EPSS 0.3%CVE-2026-39396LOWOpenBao has Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)EPSS 0.3%CVE-2025-63402MEDIUMAn issue in HCL Technologies Limited HCLTech GRAGON before v.7.6.0 allows a remote attacker to execute arbitrary code via APIs do not enforcEPSS 0.3%CVE-2025-54320MEDIUMIn Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the invite user function, leading to an email bombing vulnerabilitEPSS 0.3%CVE-2026-49337MEDIUMlibde265 has an unbounded memory leak via orphaned slice headers in `read_slice_NAL`EPSS 0.3%CVE-2025-46638HIGHDell BSAFE SSL-J contains an allocation of resources without limits or throttling vulnerability. An unauthenticated remote attacker could poEPSS 0.3%CVE-2025-71411MEDIUMIn CPDLC, Broadcast Control Frames Can Disconnect Multiple Aircraft SimultaneouslyEPSS 0.3%CVE-2025-71410MEDIUMMalicious Link Control Frames Can Cause Loss of CPDLC FunctionsEPSS 0.3%CVE-2025-10867LOWAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.3%CVE-2026-67225MEDIUMRabbitMQ: Stream-protocol frame length never validated against frame_maxEPSS 0.3%CVE-2025-3601MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.3%CVE-2026-22925HIGHA vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application is susceptible to resource exhaustionEPSS 0.3%CVE-2025-68384MEDIUMElasticsearch Allocation of Resources Without Limits or ThrottlingEPSS 0.3%CVE-2025-11482HIGHAllocation of Resources Without Limits or Throttling in the OPC-UA ServerEPSS 0.3%CVE-2025-9177HIGHRockwell Automation 1715 EtherNet/IP Comms Module Denial-Of-Service VulnerabilityEPSS 0.3%