Weaknesses of type CWE-770
1,851 resultsAlocação irrestrita de recursos
É quando a aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem limites, permitindo que um atacante esgote os recursos disponíveis do servidor. O código não valida quantidade nem tamanho, criando uma porta aberta para negação de serviço.
Example
Um endpoint HTTP que processa uploads sem validar tamanho máximo: um atacante envia múltiplos arquivos gigantes ou faz requisições em loop, consumindo toda a memória/disco até o servidor ficar indisponível para usuários legítimos.
How to mitigate
Implemente cotas e limites: defina tamanho máximo de upload, máximo de conexões por cliente, timeout para operações, e use rate limiting. Monitore consumo de recursos e rejeite requisições que violem as políticas de limite.
CVE-2026-5316MEDIUMNothings stb stb_vorbis.c setup_free allocation of resourcesEPSS 0.4%CVE-2025-3475MEDIUMWEB-T - Moderately critical - Access bypass, Denial of service - SA-CONTRIB-2025-030EPSS 0.4%CVE-2024-31617MEDIUMOpenLiteSpeed before 1.8.1 mishandles chunked encoding.EPSS 0.4%CVE-2025-55197MEDIUMpypdf's Manipulated FlateDecode streams can exhaust RAMEPSS 0.4%CVE-2026-42582HIGHNetty: HTTP/3 QPACK literal unbounded allocationEPSS 0.4%CVE-2026-33241HIGHSalvo Affected by Denial of Service via Unbounded Memory Allocation in Form Data ParsingEPSS 0.4%CVE-2024-46933HIGHAn issue was discovered in Atos Eviden BullSequana XH2140 BMC before C4EM-125: OMF_C4E 101.05.0014. Some BullSequana XH products were shippeEPSS 0.4%CVE-2023-45028MEDIUMQTS, QuTS hero, QuTScloudEPSS 0.4%CVE-2026-39904HIGHGophish 0.12.1 Denial of Service via Office Document UploadEPSS 0.4%CVE-2020-25652—A flaw was found in the spice-vdagentd daemon, where it did not properly handle client connections that can be established via the UNIX domaEPSS 0.4%CVE-2026-72888MEDIUMNet::OAuth versions before 0.32 for Perl allow memory exhaustion via unbounded caching of failed module loads in smart_requireEPSS 0.4%CVE-2026-28478HIGHOpenClaw < 2026.2.13 - Denial of Service via Unbounded Webhook Request Body BufferingEPSS 0.4%CVE-2026-33756HIGHSaleor Affected by Denial of Service via Unbounded GraphQL Query BatchingEPSS 0.4%CVE-2026-42792MEDIUMepmd permanent DoS via EMFILE on accept(2) in ertsEPSS 0.4%CVE-2025-23028MEDIUMDoS in Cilium agent DNS proxy from crafted DNS responsesEPSS 0.4%CVE-2023-34166HIGHVulnerability of system restart triggered by abnormal callbacks passed to APIs.Successful exploitation of this vulnerability may cause the sEPSS 0.4%CVE-2022-48498HIGHConfiguration defects in the secure OS module.Successful exploitation of this vulnerability will affect availability.EPSS 0.4%CVE-2026-26061HIGHFleet's unbounded request body read allows remote Denial of ServiceEPSS 0.4%CVE-2026-33658LOWRails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requestsEPSS 0.4%CVE-2025-69233MEDIUMApache CloudStack: Domain/account resources limits not honoredEPSS 0.4%