Cyber Resilience

CWE · MITRE source

CWE-770Allocation of Resources Without Limits or Throttling

Abstraction: Base · CVEs in our corpus: 2,207

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Last updated: 21 August 2026 20:21 UTC

Cumulative inbound coverage

How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.

Collective: mostly · 25 mapping(s) from 5 framework(s): CAPEC 19 (mostly) · STIG oracle linux 8 2 (mostly) · STIG oracle linux 9 2 (mostly) · STIG rhel 8 1 (mostly) · ATT&CK 1 (partial)

See the full cumulative-coverage rollup →

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • SC-10 Network Disconnect
  • SC-22 Architecture and Provisioning for Name/Address Resolution Service
  • SC-36 Distributed Processing and Storage
  • SC-47 Alternate Communications Paths
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)
  • 5 hardening rules · 3 OS baselines
Validate
Prove the fix (OWASP ASVS)
  • V15.4.4

NIST 800-53 r5 controls that address this weakness (15)AI-assisted

Showing the 11 most specific. Generic controls that address many weakness types are collapsed below.

Control Title Family Why it addresses this CWE
SC-10Network DisconnectSCImposes an inactivity-based limit on network resource allocation, throttling the number of concurrently held connections.
SC-22Architecture and Provisioning for Name/Address Resolution ServiceSCRedundant provisioning limits the effectiveness of uncontrolled allocation attacks on resolution infrastructure.
SC-36Distributed Processing and StorageSCDecentralized allocation inherently caps the resources available to any one component or attacker, countering unbounded allocation weaknesses.
CP-4Contingency Plan TestingCPPlan testing exercises resource allocation limits and throttling during simulated failures, directly addressing weaknesses that allow unbounded resource use.
CP-5Contingency Plan UpdateCPContingency plan updates ensure recovery strategies address unbounded resource allocation, making it harder for attackers to exploit lack of throttling to cause prolonged outages.
CP-7Alternate Processing SiteCPProvides continuity when unbounded resource allocation at the primary site leads to exhaustion and downtime.
SI-13Predictable Failure PreventionSIPre-planned substitution limits the window an attacker can exploit unbounded allocation to cause predictable component failure.
SI-8Spam ProtectionSIThe control enforces limits on message volume and unsolicited traffic, reducing the impact of resource allocations without throttling.
AC-10Concurrent Session ControlACThis control implements explicit throttling on session allocation, addressing the weakness of allocating resources without limits.
PL-6Security-related Activity PlanningPLExplicit planning of security-related actions requires defining limits, windows, and resource allocations, making allocation without throttling far less likely.
PM-6Measures of PerformancePMMeasures of performance include tracking allocation behavior and throttling effectiveness, reducing the window for resource exhaustion attacks.
Show 4 more broadly-applicable controls
SC-47Alternate Communications PathsSCUnbounded allocation or throttling attacks on one path are contained; the alternate path preserves organizational command functions.
SC-5Denial-of-service ProtectionSCRequires throttling and limits on resource allocation to prevent exhaustion.
SC-6Resource AvailabilitySCImplements the missing limits and throttling on resource allocation that this weakness describes.
CP-8Telecommunications ServicesCPAlternate services allow operations to continue when primary allocation of resources lacks limits or throttling.

MITRE ATT&CK techniques this weakness enables

Our own two-way CWE↔ATT&CK cross-walk — a direct mapping with no public source (the CWE→CAPEC→ATT&CK chain leaves most top weaknesses, incl. XSS and SQLi, mapped to nothing).

Direction: other covers this; this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2020-3566 KEV 8.88.60.03702020-08-29
CVE-2020-3569 KEV 8.88.60.03322020-09-23
CVE-2019-11479 8.57.50.91662019-06-19
CVE-2023-50387 8.57.51.00002024-02-14
CVE-2017-8779 8.47.50.81232017-05-04
CVE-2019-9514 8.47.50.82812019-08-13
CVE-2019-9515 8.47.50.87402019-08-13
CVE-2022-30522 8.47.50.90412022-06-09
CVE-2024-27316 8.47.50.91332024-04-04
CVE-2025-48976 8.37.50.67822025-06-16
CVE-2017-6640 8.29.80.10722017-06-08
CVE-2023-38039 8.27.50.62252023-09-15
CVE-2019-9511 8.17.50.59552019-08-13
CVE-2025-48988 8.17.50.56962025-06-16
CVE-2023-46695 7.97.50.49772023-11-02
CVE-2017-6713 7.89.80.02932017-07-06
CVE-2018-20033 7.89.80.03672019-02-25
CVE-2023-23969 7.87.50.47382023-02-01
CVE-2023-24998 7.87.50.46842023-02-20
CVE-2024-6037 7.89.10.10612024-07-10
CVE-2023-2650 7.76.50.75122023-05-30
CVE-2018-7582 7.67.50.36442018-03-09
CVE-2019-17067 7.69.80.01632019-10-01
CVE-2020-5802 7.67.50.38832020-12-29
CVE-2017-7696 7.57.50.36222017-04-14