Weaknesses of type CWE-770

1,855 results

Alocação irrestrita de recursos

É quando a aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem limites, permitindo que um atacante esgote os recursos disponíveis do servidor. O código não valida quantidade nem tamanho, criando uma porta aberta para negação de serviço.

Example

Um endpoint HTTP que processa uploads sem validar tamanho máximo: um atacante envia múltiplos arquivos gigantes ou faz requisições em loop, consumindo toda a memória/disco até o servidor ficar indisponível para usuários legítimos.

How to mitigate

Implemente cotas e limites: defina tamanho máximo de upload, máximo de conexões por cliente, timeout para operações, e use rate limiting. Monitore consumo de recursos e rejeite requisições que violem as políticas de limite.

CVE-2026-42397MEDIUMAllocation of Resources Without Limits or Throttling in Kibana Leading to Denial of ServiceEPSS 0.4%CVE-2026-35441MEDIUMDirectus Affected by GraphQL Alias Amplification Denial-of-Service Due to Missing Query Cost/Complexity LimitsEPSS 0.4%CVE-2026-72682MEDIUMAllocation of Resources Without Limits or Throttling in Kibana Leading to Denial of ServiceEPSS 0.4%CVE-2026-72659MEDIUMAllocation of Resources Without Limits or Throttling in Kibana Leading to Denial of ServiceEPSS 0.4%CVE-2024-54178MEDIUMMultiple vulnerabilities affect IBM Db2® on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data.EPSS 0.4%CVE-2025-32393HIGHAutoGPT has a DoS vulnerability in ReadRSSFeedBlockEPSS 0.4%CVE-2025-36504HIGHBIG-IP HTTP/2 vulnerabilityEPSS 0.4%CVE-2026-48504MEDIUMOpenTelemetry Rust: Unbounded memory allocation in W3C Baggage propagationEPSS 0.4%CVE-2026-67353MEDIUMguzzlehttp/guzzle before 7.15.1 Unbounded Cookie Denial of ServiceEPSS 0.4%CVE-2025-13436MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.4%CVE-2026-10832MEDIUMOrg.wildfly.security/wildfly-elytron-asn1: unbounded memory allocation in wildfly elytron asn.1 derdecoder via crafted der payloadEPSS 0.4%CVE-2025-70069HIGHAn issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXConverter.cpp and ConvertMeshMultiMaterial() metEPSS 0.4%CVE-2019-25342HIGHCentova Cast 3.2.12 - Denial of ServiceEPSS 0.4%CVE-2025-8099HIGHAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.4%CVE-2026-44500MEDIUMZEBRA: Allocation Amplification in Inbound Network DeserializersEPSS 0.4%CVE-2025-52867MEDIUMQsync CentralEPSS 0.4%CVE-2025-1516MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.4%CVE-2025-1478MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.4%CVE-2025-7449MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.4%CVE-2021-33011—All versions of the afffected TOYOPUC-PC10 Series,TOYOPUC-Plus Series,TOYOPUC-PC3J/PC2J Series, TOYOPUC-Nano Series products may not be ableEPSS 0.4%