Weaknesses of type CWE-770

1,847 results

Alocação irrestrita de recursos

É quando a aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem limites, permitindo que um atacante esgote os recursos disponíveis do servidor. O código não valida quantidade nem tamanho, criando uma porta aberta para negação de serviço.

Example

Um endpoint HTTP que processa uploads sem validar tamanho máximo: um atacante envia múltiplos arquivos gigantes ou faz requisições em loop, consumindo toda a memória/disco até o servidor ficar indisponível para usuários legítimos.

How to mitigate

Implemente cotas e limites: defina tamanho máximo de upload, máximo de conexões por cliente, timeout para operações, e use rate limiting. Monitore consumo de recursos e rejeite requisições que violem as políticas de limite.

CVE-2026-44253MEDIUMWazuh: Cluster Protocol Memory Exhaustion (DoS) via unbounded receive_str allocation and div_msg_box accumulationEPSS 0.5%CVE-2026-62641MEDIUMIn Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of service via a crafted compressed-RTF siEPSS 0.5%CVE-2026-54225HIGHApache CXF: Denial of Service attack via large attachmentsEPSS 0.5%CVE-2024-37681MEDIUMAn issue the background management system of Shanxi Internet Chuangxiang Technology Co., Ltd v1.0.1 allows a remote attacker to cause a deniEPSS 0.5%CVE-2026-64868HIGHNew API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body loggingEPSS 0.5%CVE-2025-1059HIGHCWE-770: Allocation of Resources Without Limits or Throttling vulnerability exists that could cause communications to stop when malicious paEPSS 0.5%CVE-2024-53857HIGHrPGP Potential Resource Exhaustion when handling Untrusted MessagesEPSS 0.5%CVE-2026-44240HIGHbasic-ftp allows a malicious FTP server to cause client-side denial of service via unbounded multiline control response bufferingEPSS 0.5%CVE-2026-56324HIGHCapgo - Rate Limit Bypass via User-Controlled device_id ParameterEPSS 0.5%CVE-2024-35185MEDIUMDenial of service of Minder Server with attacker-controlled REST endpointEPSS 0.5%CVE-2025-37166HIGHUnexpected shutdown in HPE Instant On Access Points after processing specific packetsEPSS 0.5%CVE-2025-57708LOWQsync CentralEPSS 0.5%CVE-2025-56223HIGHA lack of rate limiting in the component /Home/UploadStreamDocument of SigningHub v8.6.8 allows attackers to cause a Denial of Service (DoS)EPSS 0.5%CVE-2026-34755MEDIUMvLLM Affected by Denial of Service via Unbounded Frame Count in video/jpeg Base64 ProcessingEPSS 0.5%CVE-2024-21875MEDIUMDoS attack when broadcasting billboard messagesEPSS 0.5%CVE-2025-53634HIGHChall-Manager's HTTP Gateway have no header check timeout leading to potential slow loris attacksEPSS 0.5%CVE-2025-53410MEDIUMFile Station 5EPSS 0.5%CVE-2025-53409MEDIUMFile Station 5EPSS 0.5%CVE-2025-53413MEDIUMFile Station 5EPSS 0.5%CVE-2025-29770MEDIUMvLLM denial of service via outlines unbounded cache on diskEPSS 0.5%