Weaknesses of type CWE-770
1,851 resultsAlocação irrestrita de recursos
É quando a aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem limites, permitindo que um atacante esgote os recursos disponíveis do servidor. O código não valida quantidade nem tamanho, criando uma porta aberta para negação de serviço.
Example
Um endpoint HTTP que processa uploads sem validar tamanho máximo: um atacante envia múltiplos arquivos gigantes ou faz requisições em loop, consumindo toda a memória/disco até o servidor ficar indisponível para usuários legítimos.
How to mitigate
Implemente cotas e limites: defina tamanho máximo de upload, máximo de conexões por cliente, timeout para operações, e use rate limiting. Monitore consumo de recursos e rejeite requisições que violem as políticas de limite.
CVE-2024-21875MEDIUMDoS attack when broadcasting billboard messagesEPSS 0.5%CVE-2026-22036MEDIUMUndici has an unbounded decompression chain in HTTP responses on Node.js Fetch API via Content-Encoding leads to resource exhaustionEPSS 0.5%CVE-2026-2845MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.5%CVE-2025-53409MEDIUMFile Station 5EPSS 0.5%CVE-2025-53413MEDIUMFile Station 5EPSS 0.5%CVE-2025-53410MEDIUMFile Station 5EPSS 0.5%CVE-2025-53634HIGHChall-Manager's HTTP Gateway have no header check timeout leading to potential slow loris attacksEPSS 0.5%CVE-2026-26312MEDIUMStalwart Mail Server has Out-of-Memory Denial of Service via Malformed Nested MIME MessagesEPSS 0.5%CVE-2025-29770MEDIUMvLLM denial of service via outlines unbounded cache on diskEPSS 0.5%CVE-2018-25112HIGHPHOENIX CONTACT: ILC 1x1 ETH Denial of ServiceEPSS 0.5%CVE-2025-8916MEDIUMPossible DOS in processing large name constraint structures in PKIXCertPathReveiwerEPSS 0.5%CVE-2026-34826MEDIUMRack: Unbounded Range Count in get_byte_ranges Enables DoSEPSS 0.5%CVE-2026-30059HIGHAn issue in the NAS decoder component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted Registration RequeEPSS 0.5%CVE-2026-30062HIGHAn issue in the NGAP handler of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted NAS PDU.EPSS 0.5%CVE-2026-30057HIGHAn issue in the CreateUEContext handler component of free5gc v4.1.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafEPSS 0.5%CVE-2025-29899HIGHFile Station 5EPSS 0.5%CVE-2026-46673HIGHRussh: Unchecked CryptoVec allocation and growth handling is reachable from local agent inputs in current russh releases and from remote SSH traffic in historical pre-0.58.0 releasesEPSS 0.5%CVE-2026-30070HIGHAn issue in the HandleGetSharedData function of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.EPSS 0.5%CVE-2026-30051HIGHAn issue in the CreateUEContextProcedure function (/v1/ue-contexts/{supi}) of free5gc v4.1.0 allows attackers to cause a Denial of Service (EPSS 0.5%CVE-2026-84778HIGHWordPress Migrate Guru – Site Migration & Cloning plugin <= 6.65 - Denial of Service Attack vulnerabilityEPSS 0.5%