Weaknesses of type CWE-770
1,861 resultsAlocação irrestrita de recursos
É quando a aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem limites, permitindo que um atacante esgote os recursos disponíveis do servidor. O código não valida quantidade nem tamanho, criando uma porta aberta para negação de serviço.
Example
Um endpoint HTTP que processa uploads sem validar tamanho máximo: um atacante envia múltiplos arquivos gigantes ou faz requisições em loop, consumindo toda a memória/disco até o servidor ficar indisponível para usuários legítimos.
How to mitigate
Implemente cotas e limites: defina tamanho máximo de upload, máximo de conexões por cliente, timeout para operações, e use rate limiting. Monitore consumo de recursos e rejeite requisições que violem as políticas de limite.
CVE-2026-59287MEDIUMSpring for GraphQL WebSocket Client Denial of ServiceEPSS 0.4%CVE-2026-92560HIGHApache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication in the AMQP 0-10 decoderEPSS 0.4%CVE-2020-36950HIGHLaravel Nova 3.7.0 - 'range' DoSEPSS 0.4%CVE-2026-41710MEDIUMCache Exhaustion in Stateful Retries leads to Denial of ServiceEPSS 0.4%CVE-2025-27157MEDIUMMastodon's rate-limits are missing on `/auth/setup`EPSS 0.4%CVE-2026-71054MEDIUMVulnerability in Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 7u511. Easily exploitable vulneraEPSS 0.4%CVE-2026-47885HIGHSpring Framework maxPartSize Ignored in PartEventHttpMessageReaderEPSS 0.4%CVE-2025-64702MEDIUMquic-go HTTP/3 QPACK Header Expansion DoSEPSS 0.4%CVE-2024-45669MEDIUMIBM Security Verify Information Queue denial of serviceEPSS 0.4%CVE-2025-33039HIGHQsync CentralEPSS 0.4%CVE-2025-44006HIGHQsync CentralEPSS 0.4%CVE-2025-33040HIGHQsync CentralEPSS 0.4%CVE-2025-44007HIGHQsync CentralEPSS 0.4%CVE-2026-1662HIGHAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.4%CVE-2023-25153MEDIUMcontainerd OCI image importer memory exhaustionEPSS 0.4%CVE-2026-1725MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.4%CVE-2026-1718HIGHIBM® Db2® is vulnerable to a denial of service with a specially crafted query when running an AUTONOMOUS procedureEPSS 0.4%CVE-2025-0695MEDIUMAn Allocation of Resources Without Limits or Throttling vulnerability in Cesanta Frozen versions less than 1.7 allows an attacker to induce EPSS 0.4%CVE-2024-21994MEDIUMCVE-2024-21994 Denial of Service Vulnerability in StorageGRID (formerly StorageGRID Webscale)EPSS 0.4%CVE-2025-11974MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.4%