Weaknesses of type CWE-770
1,851 resultsAlocação irrestrita de recursos
É quando a aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem limites, permitindo que um atacante esgote os recursos disponíveis do servidor. O código não valida quantidade nem tamanho, criando uma porta aberta para negação de serviço.
Example
Um endpoint HTTP que processa uploads sem validar tamanho máximo: um atacante envia múltiplos arquivos gigantes ou faz requisições em loop, consumindo toda a memória/disco até o servidor ficar indisponível para usuários legítimos.
How to mitigate
Implemente cotas e limites: defina tamanho máximo de upload, máximo de conexões por cliente, timeout para operações, e use rate limiting. Monitore consumo de recursos e rejeite requisições que violem as políticas de limite.
CVE-2026-49089MEDIUMAllocation of Resources Without Limits or Throttling in Kibana Leading to Denial of ServiceEPSS 0.5%CVE-2025-64508HIGHBugsink vulnerable to unauthenticated remote DoS via crafted Brotli inputEPSS 0.5%CVE-2026-49087MEDIUMAllocation of Resources Without Limits or Throttling in Kibana Leading to Denial of ServiceEPSS 0.5%CVE-2026-29612MEDIUMOpenClaw < 2026.2.14 - Denial of Service via Large Base64 Media File DecodingEPSS 0.5%CVE-2025-53538HIGHSuricata's mishandling of data on HTTP2 stream 0 can lead to resource starvationEPSS 0.5%CVE-2026-1402MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.5%CVE-2024-31669HIGHrizin before Release v0.6.3 is vulnerable to Uncontrolled Resource Consumption via bin_pe_parse_imports, Pe_r_bin_pe_parse_var, and estimateEPSS 0.5%CVE-2026-31935HIGHSuricata http2: unbounded resource consumptionEPSS 0.5%CVE-2024-53857HIGHrPGP Potential Resource Exhaustion when handling Untrusted MessagesEPSS 0.5%CVE-2025-1059HIGHCWE-770: Allocation of Resources Without Limits or Throttling vulnerability exists that could
cause communications to stop when malicious paEPSS 0.5%CVE-2026-62641MEDIUMIn Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of service via a crafted compressed-RTF siEPSS 0.5%CVE-2024-37681MEDIUMAn issue the background management system of Shanxi Internet Chuangxiang Technology Co., Ltd v1.0.1 allows a remote attacker to cause a deniEPSS 0.5%CVE-2026-49140MEDIUMNanobot < 0.2.1 Denial of Service via Matrix Media Download HandlerEPSS 0.5%CVE-2026-82722HIGHAshAdmin LiveView events intern atoms from client input, exhausting the atom table (node DoS)EPSS 0.5%CVE-2026-71486MEDIUMvLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output boundsEPSS 0.5%CVE-2025-57708LOWQsync CentralEPSS 0.5%CVE-2025-37166HIGHUnexpected shutdown in HPE Instant On Access Points after processing specific packetsEPSS 0.5%CVE-2026-56324HIGHCapgo - Rate Limit Bypass via User-Controlled device_id ParameterEPSS 0.5%CVE-2024-35185MEDIUMDenial of service of Minder Server with attacker-controlled REST endpointEPSS 0.5%CVE-2025-56223HIGHA lack of rate limiting in the component /Home/UploadStreamDocument of SigningHub v8.6.8 allows attackers to cause a Denial of Service (DoS)EPSS 0.5%