Weaknesses of type CWE-770
1,861 resultsAlocação irrestrita de recursos
É quando a aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem limites, permitindo que um atacante esgote os recursos disponíveis do servidor. O código não valida quantidade nem tamanho, criando uma porta aberta para negação de serviço.
Example
Um endpoint HTTP que processa uploads sem validar tamanho máximo: um atacante envia múltiplos arquivos gigantes ou faz requisições em loop, consumindo toda a memória/disco até o servidor ficar indisponível para usuários legítimos.
How to mitigate
Implemente cotas e limites: defina tamanho máximo de upload, máximo de conexões por cliente, timeout para operações, e use rate limiting. Monitore consumo de recursos e rejeite requisições que violem as políticas de limite.
CVE-2025-11974MEDIUMAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.4%CVE-2026-12760HIGHDenial-of-Service Vulnerability via Malformed IPv4 Fragmentation Handling in TP-Link Tapo C200EPSS 0.4%CVE-2026-19014MEDIUMUncontrolled resource consumption in the Consul Connect authorization endpointEPSS 0.4%CVE-2026-8287MEDIUMUnrestricted File Upload in BizimHesap Information Systems' Online Pre-Accounting SoftwareEPSS 0.4%CVE-2026-95666MEDIUMUnbounded post ID array in the bulk reactions endpoint allows denial of serviceEPSS 0.4%CVE-2026-95845HIGHMoquette unbounded per-session message queues allow memory exhaustionEPSS 0.4%CVE-2020-37143MEDIUMProficySCADA for iOS 5.0.25920 - 'Password' Denial of ServiceEPSS 0.4%CVE-2026-48187MEDIUMEmail with special content can lead to DoSEPSS 0.4%CVE-2025-12767MEDIUMMultiple Vulnerabilities in IBM Concert SoftwareEPSS 0.4%CVE-2025-66838MEDIUMIn Aris v10.0.23.0.3587512 and before, the file upload functionality does not enforce any rate limiting or throttling, allowing users to uplEPSS 0.4%CVE-2026-56309MEDIUMCapgo - Plan Bypass via Unrestricted Attachment Upload EndpointEPSS 0.4%CVE-2025-15317MEDIUMTanium addressed an uncontrolled resource consumption vulnerability in Tanium Server.EPSS 0.4%CVE-2026-53493MEDIUMContainerd has image-pull DoS via crafted OCI index graph amplificationEPSS 0.4%CVE-2026-19517MEDIUMImproper Validation of Specified Quantity in Input and Allocation of Resources Without Limits or Throttling vulnerability in Samsung Open SoEPSS 0.4%CVE-2026-1659HIGHAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.4%CVE-2026-8683MEDIUMOverly long URLs crash the Mattermost Desktop AppEPSS 0.4%CVE-2025-52494HIGHAdacore Ada Web Server (AWS) before 25.2 is vulnerable to a denial-of-service (DoS) condition due to improper handling of SSL handshakes durEPSS 0.4%CVE-2026-13586MEDIUMPKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS)EPSS 0.4%CVE-2025-64334HIGHSuricata is vulnerable to unbounded memory growth for decompressionEPSS 0.4%CVE-2025-3734MEDIUMStage File Proxy - Moderately critical - Denial of Service - SA-CONTRIB-2025-035EPSS 0.4%