Weaknesses of type CWE-770
1,846 resultsAlocação irrestrita de recursos
É quando a aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem limites, permitindo que um atacante esgote os recursos disponíveis do servidor. O código não valida quantidade nem tamanho, criando uma porta aberta para negação de serviço.
Example
Um endpoint HTTP que processa uploads sem validar tamanho máximo: um atacante envia múltiplos arquivos gigantes ou faz requisições em loop, consumindo toda a memória/disco até o servidor ficar indisponível para usuários legítimos.
How to mitigate
Implemente cotas e limites: defina tamanho máximo de upload, máximo de conexões por cliente, timeout para operações, e use rate limiting. Monitore consumo de recursos e rejeite requisições que violem as políticas de limite.
CVE-2025-66418HIGHurllib3 allows an unbounded number of links in the decompression chainEPSS 0.7%CVE-2025-61028HIGHAn issue in the time_t_to_dt component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via craftEPSS 0.7%CVE-2023-2666MEDIUMAllocation of Resources Without Limits or Throttling in froxlor/froxlorEPSS 0.7%CVE-2022-3439MEDIUMAllocation of Resources Without Limits or Throttling in ikus060/rdiffwebEPSS 0.7%CVE-2024-55563MEDIUMBitcoin Core through 27.2 allows transaction-relay jamming via an off-chain protocol attack, a related issue to CVE-2024-52913. For example,EPSS 0.7%CVE-2026-40192HIGHPillow is vulnerable to a FITS GZIP decompression bombEPSS 0.7%CVE-2022-22211HIGHJunos OS Evolved: PTX Series: Multiple FPCs become unreachable due to continuous polling of specific SNMP OIDEPSS 0.7%CVE-2026-44488HIGHAxios: Allocation of Resources Without Limits or Throttling in axiosEPSS 0.7%CVE-2023-20155HIGHA vulnerability in a logging API in Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to causEPSS 0.7%CVE-2024-35231HIGHrack-contrib vulnerable to Denial of Service due to the unconstrained value of the incoming "profiler_runs" parameterEPSS 0.7%CVE-2023-51339MEDIUMA lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Event Ticketing System v1.0 allows attackers to send an excessive amoEPSS 0.7%CVE-2026-27979MEDIUMNext.js: Unbounded postponed resume buffering can lead to DoSEPSS 0.7%CVE-2026-27857MEDIUMSending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands will result in client EPSS 0.7%CVE-2020-36946HIGHSyncBreeze 10.0.28 - 'login' Denial of ServiceEPSS 0.7%CVE-2023-34389MEDIUMAllocation of resources without limits could lead to denial of serviceEPSS 0.7%CVE-2023-22323HIGHBIG-IP SSL OCSP Authentication profile vulnerabilityEPSS 0.7%CVE-2022-45434MEDIUMSome Dahua software products have a vulnerability of unauthenticated un-throttled ICMP requests on remote DSS Server. After bypassing the fiEPSS 0.7%CVE-2022-31184MEDIUMEmail activation route can be abused by spammers in DiscourseEPSS 0.7%CVE-2024-29902MEDIUMCosign vulnerable to system-wide denial of service via malicious attachmentsEPSS 0.7%CVE-2023-41038HIGHServer crash when using specific form of SET BIND statementEPSS 0.7%