Fallos del tipo CWE-770
1864 resultadosAlocação sem limite de recursos
A aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem impor limites, permitindo que um atacante esgote os recursos do sistema. O risco é negação de serviço: a aplicação ou servidor inteiro pode travar quando os recursos acabam.
Ejemplo
Um servidor web aceita requisições sem limitar quantas conexões simultâneas um único usuário pode abrir, ou um upload sem verificar tamanho máximo. Um atacante abre milhões de conexões ou envia arquivos gigantes até a memória/disco encher.
Cómo mitigar
Implemente quotas e limites por usuário/origem (rate limiting, máximo de conexões simultâneas, tamanho máximo de upload). Monitore consumo de recursos e recuse requisições que violem os limites com erro 429 ou similar.
CVE-2021-47876MEDIUMGeoGebra Classic 5.0.631.0-d - Denial of ServiceEPSS 0.3%CVE-2021-47877MEDIUMGeoGebra Graphing Calculator 6.0.631.0 - Denial Of ServiceEPSS 0.3%CVE-2024-4029MEDIUMWildfly: no timeout for eap management interface may lead to denial of service (dos)EPSS 0.3%CVE-2025-24086MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, mEPSS 0.3%CVE-2025-0122MEDIUMPrisma SD-WAN: Denial of Service (DoS) Vulnerability Through Burst of Crafted PacketsEPSS 0.3%CVE-2026-1848HIGHConnections received from the proxy port may not count towards total accepted connectionsEPSS 0.3%CVE-2025-68934MEDIUMDiscourse Has Denial of Service (DoS) Vulnerability in Drafts Creation EndpointEPSS 0.3%CVE-2026-24458HIGHDoS attack via login attempts with multi-megabyte passwordsEPSS 0.3%CVE-2026-96764MEDIUMkvcache-ai mooncake Regular Expression GetReplicaListByRegex allocation of resourcesEPSS 0.3%CVE-2022-20490HIGHIn multiple functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. ThisEPSS 0.3%CVE-2022-20492HIGHIn many functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This couEPSS 0.3%CVE-2026-22018LOWVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: LibrariEPSS 0.3%CVE-2026-44247MEDIUMVolcano: Webhook server vulnerable to OOM due to unbounded HTTP request body sizeEPSS 0.3%CVE-2025-29916MEDIUMSuricata datasets: ruleset declared settings can lead to resource starvationEPSS 0.3%CVE-2025-29917MEDIUMSuricata decode_base64: signature can do large memory allocationEPSS 0.3%CVE-2025-31990MEDIUMHCL DevOps Velocity is susceptible to a Denial of Service vulnerabilityEPSS 0.3%CVE-2026-54429MEDIUMA vulnerability has been identified in SIMATIC S7-PLCSIM Advanced (All versions). Affected devices do not properly handle high-volume multicEPSS 0.3%CVE-2026-48990MEDIUMjoserfc: b64=false RFC7797 JWS payloads bypass JWSRegistry payload-size limits during deserializationEPSS 0.3%CVE-2024-5210MEDIUMA denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to pEPSS 0.3%CVE-2024-6004MEDIUMA denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to dEPSS 0.3%