Weaknesses of type CWE-770
1,861 resultsAlocação irrestrita de recursos
É quando a aplicação aloca recursos (memória, conexões, arquivos, threads) em nome do usuário sem limites, permitindo que um atacante esgote os recursos disponíveis do servidor. O código não valida quantidade nem tamanho, criando uma porta aberta para negação de serviço.
Example
Um endpoint HTTP que processa uploads sem validar tamanho máximo: um atacante envia múltiplos arquivos gigantes ou faz requisições em loop, consumindo toda a memória/disco até o servidor ficar indisponível para usuários legítimos.
How to mitigate
Implemente cotas e limites: defina tamanho máximo de upload, máximo de conexões por cliente, timeout para operações, e use rate limiting. Monitore consumo de recursos e rejeite requisições que violem as políticas de limite.
CVE-2025-65942LOWVictoriaMetrics Snappy Decoder DoS Vulnerability is Causing OOMEPSS 0.3%CVE-2025-59045HIGHStalwart vulnerable to Memory Exhaustion via CalDAV Event ExpansionEPSS 0.3%CVE-2026-29795MEDIUMstellar-xdr: `StringM::from_str` bypasses max length validationEPSS 0.3%CVE-2026-6060MEDIUMPossible DoS via SQL BoxEPSS 0.3%CVE-2026-15055MEDIUMPKCS#8 / PBES2 decryptors honour unbounded KDF cost from inputEPSS 0.3%CVE-2025-61775MEDIUMVickey's unexpired email confirmation link can be reused to send repeated confirmation emailsEPSS 0.3%CVE-2025-14870HIGHAllocation of Resources Without Limits or Throttling in GitLabEPSS 0.3%CVE-2026-82439CRITICALApache Storm DRPC: Unauthenticated Unbounded Memory Growth in DRPCEPSS 0.3%CVE-2026-45712MEDIUMMailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write)EPSS 0.3%CVE-2025-59778HIGHVELOS partition container network vulnerabilityEPSS 0.3%CVE-2026-0897HIGHDenial of Service in Keras via Excessive Memory Allocation in HDF5 MetadataEPSS 0.3%CVE-2024-4781MEDIUMA denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to cEPSS 0.3%CVE-2025-61595HIGHMANTRA tx gas limit is not enforced in send hooksEPSS 0.3%CVE-2025-49000LOWInvenTree has uncontrolled memory allocation via built-in label-sheet pluginEPSS 0.3%CVE-2025-55199MEDIUMHelm Charts with Specific JSON Schema Values Can Cause Memory ExhaustionEPSS 0.3%CVE-2026-27932HIGHjoserfc PBES2 p2c Unbounded Iteration Count enables Denial of Service (DoS)EPSS 0.3%CVE-2025-66487LOWMultiple vulnerabilities have been addressed in IBM Aspera SharesEPSS 0.3%CVE-2025-47208MEDIUMQTS, QuTS heroEPSS 0.3%CVE-2026-16971MEDIUMDFIR-IRIS Missing Brute Force Protection in OTP ValidationEPSS 0.3%CVE-2021-28715MEDIUMGuest can force Linux netback driver to hog large amounts of kernel memory T[his CNA information record relates to multiple CVEs; the text eEPSS 0.3%