Weaknesses of type CWE-770

1,852 results

Alocação irrestrita de recursos

É quando a aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem limites, permitindo que um atacante esgote os recursos disponíveis do servidor. O código não valida quantidade nem tamanho, criando uma porta aberta para negação de serviço.

Example

Um endpoint HTTP que processa uploads sem validar tamanho máximo: um atacante envia múltiplos arquivos gigantes ou faz requisições em loop, consumindo toda a memória/disco até o servidor ficar indisponível para usuários legítimos.

How to mitigate

Implemente cotas e limites: defina tamanho máximo de upload, máximo de conexões por cliente, timeout para operações, e use rate limiting. Monitore consumo de recursos e rejeite requisições que violem as políticas de limite.

CVE-2026-30051HIGHAn issue in the CreateUEContextProcedure function (/v1/ue-contexts/{supi}) of free5gc v4.1.0 allows attackers to cause a Denial of Service (EPSS 0.5%CVE-2026-30067HIGHAn issue in the complexQueryFilterSubprocess function in the NRF Discovery service of free5gc v4.0.1 allows attackers to cause a Denial of SEPSS 0.5%CVE-2026-41007HIGHSpring HATEOAS heap exhaustion through unbounded internal cachingEPSS 0.5%CVE-2026-34826MEDIUMRack: Unbounded Range Count in get_byte_ranges Enables DoSEPSS 0.5%CVE-2026-54716HIGHValhalla: Degenerate exclude_polygons (collinear points, zero area) causes OOM in /sources_to_targetsEPSS 0.5%CVE-2026-45290HIGHCloudburst Network has DoS in RakNet connection handling due to missing bound checksEPSS 0.5%CVE-2025-29890HIGHFile Station 5EPSS 0.5%CVE-2026-35401HIGHSaleor has a resource exhaustion vulnerability in GraphQL queriesEPSS 0.5%CVE-2026-40629HIGHBIG-IP SSL/TLS vulnerabilityEPSS 0.5%CVE-2026-40881MEDIUMZebra: addr/addrv2 Deserialization Resource ExhaustionEPSS 0.5%CVE-2026-46702HIGHRussh: Post-decompression SSH packet size was not bounded, allowing remote oversized compressed packetsEPSS 0.5%CVE-2025-7737HIGHDoS Vulnerability in 10G iSCSI Interface of Hitachi Virtual Storage PlatformEPSS 0.5%CVE-2026-81285HIGHWordPress Smush Image Compression and Optimization plugin <= 4.2.0 - Denial of Service Attack vulnerabilityEPSS 0.5%CVE-2026-30071HIGHAn issue in the RechargePut function of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.EPSS 0.5%CVE-2026-30059HIGHAn issue in the NAS decoder component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted Registration RequeEPSS 0.5%CVE-2025-55197MEDIUMpypdf's Manipulated FlateDecode streams can exhaust RAMEPSS 0.5%CVE-2025-62706MEDIUMAuthlib : JWE zip=DEF decompression bomb enables DoSEPSS 0.5%CVE-2024-1666HIGHUnauthorized Radar Creation in lunary-ai/lunaryEPSS 0.5%CVE-2024-28760MEDIUMIBM App Connect Enterprise denial of serviceEPSS 0.5%CVE-2024-3760HIGHEmail Bombing Vulnerability in lunary-ai/lunaryEPSS 0.5%