Weaknesses of type CWE-770
1,833 resultsAlocação irrestrita de recursos
É quando a aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem limites, permitindo que um atacante esgote os recursos disponíveis do servidor. O código não valida quantidade nem tamanho, criando uma porta aberta para negação de serviço.
Example
Um endpoint HTTP que processa uploads sem validar tamanho máximo: um atacante envia múltiplos arquivos gigantes ou faz requisições em loop, consumindo toda a memória/disco até o servidor ficar indisponível para usuários legítimos.
How to mitigate
Implemente cotas e limites: defina tamanho máximo de upload, máximo de conexões por cliente, timeout para operações, e use rate limiting. Monitore consumo de recursos e rejeite requisições que violem as políticas de limite.
CVE-2026-50525HIGH.NET Denial of Service VulnerabilityEPSS 0.6%CVE-2024-31446HIGHOpenComputers Denial of Service using xpcallEPSS 0.6%CVE-2026-42440HIGHApache OpenNLP: OOM DoS via Unbounded Array Allocation in AbstractModelReaderEPSS 0.6%CVE-2024-48809HIGHAn issue in Open Networking Foundations sdran-in-a-box v.1.4.3 and onos-a1t v.0.2.3 allows a remote attacker to cause a denial of service viEPSS 0.6%CVE-2026-55078MEDIUMCoder: Zip upload decompression lacks aggregate size limit, enabling denial of serviceEPSS 0.6%CVE-2024-50311MEDIUMGraphql: denial of service (dos) vulnerability via graphql batchingEPSS 0.6%CVE-2025-2813HIGHHTTP Service DoS VulnerabilityEPSS 0.6%CVE-2025-10497HIGHAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.6%CVE-2026-26313MEDIUMGo Ethereum affected by DoS via malicious p2p messageEPSS 0.6%CVE-2023-32481MEDIUM
Wyse Management Suite versions prior to 4.0 contain a denial-of-service vulnerability. An authenticated malicious user can flood the configEPSS 0.6%CVE-2025-24317MEDIUMAllocation of resources without limits or throttling issue exists in HMI ViewJet C-more series and HMI GC-A2 series, which may allow a remotEPSS 0.6%CVE-2024-31881MEDIUMIBM Db2 denial of serviceEPSS 0.6%CVE-2026-33332MEDIUMNiceGUI's unvalidated chunk size parameter in media routes can cause memory exhaustionEPSS 0.6%CVE-2025-8537MEDIUMAxiomatic Bento4 mp4decrypt Mp4Decrypt.cpp SetDataSize allocation of resourcesEPSS 0.6%CVE-2021-47137CRITICALnet: lantiq: fix memory corruption in RX ringEPSS 0.6%CVE-2024-50285HIGHksmbd: check outstanding simultaneous SMB operationsEPSS 0.6%CVE-2024-37302HIGHSynapse denial of service through media disk space consumptionEPSS 0.6%CVE-2023-49559LOWAn issue in vektah gqlparser open-source-library v.2.5.10 allows a remote attacker to cause a denial of service via a crafted script to the EPSS 0.6%CVE-2025-8014HIGHAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.6%CVE-2023-51334MEDIUMA lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Cinema Booking System v1.0 allows attackers to send an excessive amouEPSS 0.6%