Weaknesses of type CWE-770
1,852 resultsAlocação irrestrita de recursos
É quando a aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem limites, permitindo que um atacante esgote os recursos disponíveis do servidor. O código não valida quantidade nem tamanho, criando uma porta aberta para negação de serviço.
Example
Um endpoint HTTP que processa uploads sem validar tamanho máximo: um atacante envia múltiplos arquivos gigantes ou faz requisições em loop, consumindo toda a memória/disco até o servidor ficar indisponível para usuários legítimos.
How to mitigate
Implemente cotas e limites: defina tamanho máximo de upload, máximo de conexões por cliente, timeout para operações, e use rate limiting. Monitore consumo de recursos e rejeite requisições que violem as políticas de limite.
CVE-2026-84778HIGHWordPress Migrate Guru – Site Migration & Cloning plugin <= 6.65 - Denial of Service Attack vulnerabilityEPSS 0.5%CVE-2026-41227HIGHBIG-IP HTTP/2 Layer 7 Dos Protection vulnerabilityEPSS 0.5%CVE-2025-29898MEDIUMQsync CentralEPSS 0.5%CVE-2024-47401MEDIUMDoS via Amplified GraphQL Response in PlaybooksEPSS 0.5%CVE-2026-40629HIGHBIG-IP SSL/TLS vulnerabilityEPSS 0.5%CVE-2026-30071HIGHAn issue in the RechargePut function of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.EPSS 0.5%CVE-2026-44697HIGHKlever-Go MultiDataInterceptor: remote OOM via crafted compressed P2P payloadEPSS 0.5%CVE-2026-30057HIGHAn issue in the CreateUEContext handler component of free5gc v4.1.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafEPSS 0.5%CVE-2026-40881MEDIUMZebra: addr/addrv2 Deserialization Resource ExhaustionEPSS 0.5%CVE-2025-29899HIGHFile Station 5EPSS 0.5%CVE-2026-46673HIGHRussh: Unchecked CryptoVec allocation and growth handling is reachable from local agent inputs in current russh releases and from remote SSH traffic in historical pre-0.58.0 releasesEPSS 0.5%CVE-2026-54609HIGHQTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwardingEPSS 0.5%CVE-2026-48702HIGHRekor has an OOM Condition due to Unbounded gzip Decompression in Alpine APK Parsing LogicEPSS 0.5%CVE-2025-53628MEDIUMcpp-httplib does not limit the length of a lineEPSS 0.5%CVE-2026-30050HIGHAn issue in the ModifyAMFEventSubscriptionProcedure function (processor/event_exposure.go) of free5gc v4.1.0 allows attackers to cause a DenEPSS 0.5%CVE-2026-84776HIGHWordPress MalCare Security plugin <= 6.69 - Denial of Service Attack vulnerabilityEPSS 0.5%CVE-2026-41716HIGHSpring Data web support unbounded negative-result cache keyed on attacker-supplied property namesEPSS 0.5%CVE-2026-73997HIGHWordPress Starter Templates by Kadence WP plugin <= 2.3.3 - Denial of Service Attack vulnerabilityEPSS 0.5%CVE-2026-30060HIGHAn issue in free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) when parsing crafted SUCI data during UE registration.EPSS 0.5%CVE-2026-48888HIGHWordPress WooCommerce plugin < 11.1.0 - Denial of Service Attack vulnerabilityEPSS 0.5%