Weaknesses of type CWE-770
1,851 resultsAlocação irrestrita de recursos
É quando a aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem limites, permitindo que um atacante esgote os recursos disponíveis do servidor. O código não valida quantidade nem tamanho, criando uma porta aberta para negação de serviço.
Example
Um endpoint HTTP que processa uploads sem validar tamanho máximo: um atacante envia múltiplos arquivos gigantes ou faz requisições em loop, consumindo toda a memória/disco até o servidor ficar indisponível para usuários legítimos.
How to mitigate
Implemente cotas e limites: defina tamanho máximo de upload, máximo de conexões por cliente, timeout para operações, e use rate limiting. Monitore consumo de recursos e rejeite requisições que violem as políticas de limite.
CVE-2026-81699HIGHopenssl_encrypt before 1.4.9 Denial of Service via unbounded KDF costEPSS 0.5%CVE-2026-25579CRITICALNavidrome affected by Denial of Service and disk exhaustion via oversized `size` parameter in `/rest/getCoverArt` and `/share/img/<token>` endpointsEPSS 0.5%CVE-2024-45526MEDIUMAn issue was discovered in OPC Foundation OPCFoundation/UA-.NETStandard through 1.5.374.78. A remote attacker can send requests with invalidEPSS 0.5%CVE-2024-21539HIGHVersions of the package @eslint/plugin-kit before 0.2.3 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper inputEPSS 0.5%CVE-2026-59246MEDIUMZero-length HTTP/2 CONTINUATION frames bypass Mint's header-block byte-size cap and exhaust client memoryEPSS 0.5%CVE-2025-24341MEDIUMA vulnerability in the web application of ctrlX OS allows a remote authenticated (low-privileged) attacker to induce a Denial-of-Service (DoEPSS 0.5%CVE-2026-58229HIGHUnbounded HTTP/1 response-header and chunked-trailer accumulation in Mint causes memory-exhaustion DoSEPSS 0.5%CVE-2026-56149MEDIUMAllocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of ServiceEPSS 0.5%CVE-2020-25650—A flaw was found in the way the spice-vdagentd daemon handled file transfers from the host system to the virtual machine. Any unprivileged lEPSS 0.5%CVE-2025-14871HIGHAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.5%CVE-2024-34703HIGHBotan Vulnerable to Denial of Service Due to Overly Large Elliptic Curve ParametersEPSS 0.5%CVE-2026-78662HIGHPrevent DoS on deadlocked undecided channel in golang.org/x/crypto/sshEPSS 0.5%CVE-2023-51309MEDIUMA lack of rate limiting in the 'Email Settings' feature of PHPJabbers Car Park Booking System v3.0 allows attackers to send an excessive amoEPSS 0.5%CVE-2018-25108HIGHWAGO: Denial of service in 750-8xx controller due to uncontrolled resource consumptionEPSS 0.5%CVE-2023-51310MEDIUMA lack of rate limiting in the 'Forgot Password', 'Email Settings' feature of PHPJabbers Car Park Booking System v3.0 allows attackers to seEPSS 0.5%CVE-2020-36949MEDIUMTapinRadio 2.13.7 - Denial of ServiceEPSS 0.5%CVE-2024-7113HIGHAllocation of Resources Without Limits or Throttling in AVEVA SuiteLink ServerEPSS 0.5%CVE-2025-54500MEDIUMHTTP/2 VulnerabilityEPSS 0.5%CVE-2024-7803MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.5%CVE-2025-32381MEDIUMDenial of Service by abusing xgrammar unbounded cache in memoryEPSS 0.5%