Weaknesses of type CWE-770
1,836 resultsAlocação irrestrita de recursos
É quando a aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem limites, permitindo que um atacante esgote os recursos disponíveis do servidor. O código não valida quantidade nem tamanho, criando uma porta aberta para negação de serviço.
Example
Um endpoint HTTP que processa uploads sem validar tamanho máximo: um atacante envia múltiplos arquivos gigantes ou faz requisições em loop, consumindo toda a memória/disco até o servidor ficar indisponível para usuários legítimos.
How to mitigate
Implemente cotas e limites: defina tamanho máximo de upload, máximo de conexões por cliente, timeout para operações, e use rate limiting. Monitore consumo de recursos e rejeite requisições que violem as políticas de limite.
CVE-2025-21536MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.39 aEPSS 1.0%CVE-2025-21534MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Performance Schema). Supported versions that are affected areEPSS 1.0%CVE-2026-57220HIGHRabbitMQ: Stream listener does not enforce configured frame-size limit during authentication, permitting unauth'd mem-exhaust DoSEPSS 1.0%CVE-2026-47774HIGHEnvoy vulnerable to HTTP/2 memory exhaustion via cookie header size bypass and HPACK amplificationEPSS 1.0%CVE-2025-21499MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.4.3 and prioEPSS 1.0%CVE-2023-38507HIGHStrapi Improper Rate Limiting vulnerabilityEPSS 1.0%CVE-2026-18649HIGHGstreamer1-plugins-good: gst-plugins-good: unbounded memory growth in rtph264depay and rtph265depay rtp depayloadersEPSS 1.0%CVE-2021-0285HIGHJunos OS: QFX5000 Series and EX4600 Series: Continuous traffic destined to a device configured with MC-LAG leading to nodes losing their control connection which can impact trafficEPSS 1.0%CVE-2026-27601HIGHUnderscore.js has unlimited recursion in _.flatten and _.isEqual, potential for DoS attackEPSS 1.0%CVE-2025-21492MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.36 aEPSS 1.0%CVE-2018-3738—protobufjs is vulnerable to ReDoS when parsing crafted invalid .proto files.EPSS 1.0%CVE-2023-28119HIGHcrewjam/saml vulnerable to Denial Of Service Via Deflate Decompression BombEPSS 1.0%CVE-2024-32663HIGHSuricata 's http2 parser contains an improper compressed header handling can lead to resource starvationEPSS 1.0%CVE-2022-22278—A vulnerability in SonicOS CFS (Content filtering service) returns a large 403 forbidden HTTP response message to the source address when usEPSS 1.0%CVE-2023-30636HIGHTiKV 6.1.2 allows remote attackers to cause a denial of service (fatal error, with RpcStatus UNAVAILABLE for "not leader") upon an attempt tEPSS 1.0%CVE-2022-43768HIGHA vulnerability has been identified in SIMATIC CP 1242-7 V2 (6GK7242-7KX31-0XE0) (All versions < V3.4.29), SIMATIC CP 1243-1 (6GK7243-1BX30-EPSS 1.0%CVE-2022-32958HIGHTEAMPLUS TECHNOLOGY INC. Teamplus Pro - Allocation of Resources Without Limits or ThrottlingEPSS 1.0%CVE-2024-2818MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.9%CVE-2024-36462HIGHAllocation of resources without limits or throttling (uncontrolled resource consumption)EPSS 0.9%CVE-2023-26285MEDIUMIBM MQ denial of serviceEPSS 0.9%