Weaknesses of type CWE-770

1,813 results

Alocação irrestrita de recursos

É quando a aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem limites, permitindo que um atacante esgote os recursos disponíveis do servidor. O código não valida quantidade nem tamanho, criando uma porta aberta para negação de serviço.

Example

Um endpoint HTTP que processa uploads sem validar tamanho máximo: um atacante envia múltiplos arquivos gigantes ou faz requisições em loop, consumindo toda a memória/disco até o servidor ficar indisponível para usuários legítimos.

How to mitigate

Implemente cotas e limites: defina tamanho máximo de upload, máximo de conexões por cliente, timeout para operações, e use rate limiting. Monitore consumo de recursos e rejeite requisições que violem as políticas de limite.

CVE-2024-41743HIGHIBM TXSeries for Multiplatforms denial of serviceEPSS 0.6%CVE-2023-36521HIGHA vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3.4), SIMATIC MV540 S (All versions < V3.3.4), SIMATIC MV550 H (AlEPSS 0.6%CVE-2026-39804HIGHWebSocket permessage-deflate inflate has no output-size cap in banditEPSS 0.6%CVE-2026-69152HIGHbrace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigationEPSS 0.6%CVE-2026-32145HIGHMultipart form body parser bypasses body size limits in wispEPSS 0.6%CVE-2026-42006MEDIUMAn attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomplete, only blocking onEPSS 0.6%CVE-2023-37900LOWCrossplane vulnerable to denial of service from large imageEPSS 0.6%CVE-2025-0189HIGHDenial of Service in aimhubio/aimEPSS 0.6%CVE-2026-8468HIGHUnbounded buffer accumulation in multipart header parsing causes denial of service in plugEPSS 0.6%CVE-2024-43709MEDIUMElasticsearch allocation of resources without limits or throttling leads to crashEPSS 0.6%CVE-2023-41043MEDIUMDiscourse DoS via SvgSprite cacheEPSS 0.6%CVE-2024-5208MEDIUMUncontrolled Resource Consumption in mintplex-labs/anything-llmEPSS 0.6%CVE-2023-40588MEDIUMDiscourse DoS via 2FA and Security Key NamesEPSS 0.6%CVE-2023-38405On Crestron 3-Series Control Systems before 1.8001.0187, crafting and sending a specific BACnet packet can cause a crash.EPSS 0.6%CVE-2025-1451HIGHInsufficient Patch Leading to DoS in parisneo/lollms-webuiEPSS 0.6%CVE-2024-11316HIGHFilesize CheckEPSS 0.6%CVE-2024-0081HIGH NVIDIA NeMo framework for Ubuntu contains a vulnerability in tools/asr_webapp where an attacker may cause an allocation of resources withouEPSS 0.6%CVE-2026-32280HIGHUnexpected work during chain building in crypto/x509EPSS 0.6%CVE-2024-10714HIGHDenial of Service in binary-husky/gpt_academicEPSS 0.6%CVE-2024-8018HIGHDenial of Service (DOS) in imartinez/privategptEPSS 0.6%