Weaknesses of type CWE-770
1,861 resultsAlocação irrestrita de recursos
É quando a aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem limites, permitindo que um atacante esgote os recursos disponíveis do servidor. O código não valida quantidade nem tamanho, criando uma porta aberta para negação de serviço.
Example
Um endpoint HTTP que processa uploads sem validar tamanho máximo: um atacante envia múltiplos arquivos gigantes ou faz requisições em loop, consumindo toda a memória/disco até o servidor ficar indisponível para usuários legítimos.
How to mitigate
Implemente cotas e limites: defina tamanho máximo de upload, máximo de conexões por cliente, timeout para operações, e use rate limiting. Monitore consumo de recursos e rejeite requisições que violem as políticas de limite.
CVE-2026-47874MEDIUMReactor Netty HTTP Server Denial of Service With Pipelined RequestsEPSS 0.4%CVE-2026-19015MEDIUMUncontrolled resource consumption in the Consul Connect CA roots endpointEPSS 0.4%CVE-2026-54270MEDIUMprotobufjs: Memory amplification from preserved unknown fields in binary decodeEPSS 0.4%CVE-2026-84775MEDIUMWordPress Really Simple SSL plugin <= 9.8.0 - Denial of Service Attack vulnerabilityEPSS 0.4%CVE-2026-59323MEDIUMMicrometer Tracing Brave Bridge W3C Baggage propagation DoS vulnerabilityEPSS 0.4%CVE-2026-1660MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.4%CVE-2026-84780MEDIUMWordPress WP Go Maps plugin <= 10.1.08 - Denial of Service Attack vulnerabilityEPSS 0.4%CVE-2026-53596MEDIUMFreeScout has unrestricted file upload without rate limiting that leads to resource exhaustion (DoS)EPSS 0.4%CVE-2025-24312HIGHBIG-IP AFM vulnerabilityEPSS 0.4%CVE-2026-27695MEDIUMzae-limiter: DynamoDB hot partition throttling enables per-entity Denial of ServiceEPSS 0.4%CVE-2024-6098MEDIUMPTC Kepware ThingWorx Kepware Server Allocation of Resources Without Limits or ThrottlingEPSS 0.4%CVE-2026-41310MEDIUMOpenTelemetry .NET Zipkin exporter has unbounded remote endpoint cache leading to memory growthEPSS 0.4%CVE-2025-4416HIGHEvents Log Track - Moderately critical - Denial of Service - SA-CONTRIB-2025-059EPSS 0.4%CVE-2025-27144MEDIUMGo JOSE's Parsing Vulnerable to Denial of ServiceEPSS 0.4%CVE-2025-69228MEDIUMAIOHTTP vulnerable to denial of service through large payloadsEPSS 0.4%CVE-2025-65113MEDIUMClipBucket v5 Unauthenticated Object Flagging VulnerabilityEPSS 0.4%CVE-2025-43211MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS SeEPSS 0.4%CVE-2026-77121MEDIUMNexus Repository 3 - Denial of Service via Unbounded Maven POM Metadata FieldsEPSS 0.4%CVE-2026-5762MEDIUMReportIncident DiscussionTools integration causes slow requestsEPSS 0.4%CVE-2024-6600MEDIUMMemory corruption in WebGL APIEPSS 0.4%