CWE-674— Uncontrolled Recursion
The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.— MITRE CWE catalog
470 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-674page 6 of 10
- CVE-2024-0211HIGHCVSS 7.5EG 7.82024-01-03
DOCSIS dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture file
- CVE-2024-12910MEDIUMCVSS 5.9EG 5.92025-03-20
A vulnerability in the `KnowledgeBaseWebReader` class of the run-llama/llama_index repository, version latest, allows an attacker to cause a Denial of Service (DoS) by controlling a URL variable to contain the root URL. This leads to infin…
- CVE-2024-1899MEDIUMCVSS 5.3EG 5.32024-02-26
An issue in the anchors subparser of Showdownjs versions <= 2.1.0 could allow a remote attacker to cause denial of service conditions.
- CVE-2024-20311HIGHCVSS 8.6EG 8.62024-03-27
A vulnerability in the Locator ID Separation Protocol (LISP) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. This vulnerability is due to the…
- CVE-2024-25111HIGHCVSS 8.6EG 8.92024-03-06
Squid is a web proxy cache. Starting in version 3.5.27 and prior to version 6.8, Squid may be vulnerable to a Denial of Service attack against HTTP Chunked decoder due to an uncontrolled recursion bug. This problem allows a remote attacker…
- CVE-2024-25112MEDIUMCVSS 5.5EG 5.52024-02-12
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A denial-of-service was found in Exiv2 version v0.28.1: an unbounded recursion can cause Exiv2 to crash by exhaustin…
- CVE-2024-27454HIGHCVSS 7.5EG 7.52024-02-26
orjson.loads in orjson before 3.9.15 does not limit recursion for deeply nested JSON documents.
- CVE-2024-28243MEDIUMCVSS 6.5EG 6.52024-03-25
KaTeX is a JavaScript library for TeX math rendering on the web. KaTeX users who render untrusted mathematical expressions could encounter malicious input using `\edef` that causes a near-infinite loop, despite setting `maxExpand` to avoid…
- CVE-2024-28244MEDIUMCVSS 6.5EG 6.52024-03-25
KaTeX is a JavaScript library for TeX math rendering on the web. KaTeX users who render untrusted mathematical expressions could encounter malicious input using `\def` or `\newcommand` that causes a near-infinite loop, despite setting `max…
- CVE-2024-2965MEDIUMCVSS 4.7EG 4.72024-06-06
A Denial-of-Service (DoS) vulnerability exists in the `SitemapLoader` class of the `langchain-ai/langchain` repository, affecting all versions. The `parse_sitemap` method, responsible for parsing sitemaps and extracting URLs, lacks a mecha…
- CVE-2024-29904HIGHCVSS 7.5EG 7.52024-03-29
CodeIgniter is a PHP full-stack web framework A vulnerability was found in the Language class that allowed DoS attacks. This vulnerability can be exploited by an attacker to consume a large amount of memory on the server. Upgrade to v4.4.7…
- CVE-2024-31228MEDIUMCVSS 5.5EG 5.52024-10-07
Redis is an open source, in-memory database that persists on disk. Authenticated users can trigger a denial-of-service by using specially crafted, long string match patterns on supported commands such as `KEYS`, `SCAN`, `PSUBSCRIBE`, `FUNC…
- CVE-2024-3247LOWCVSS 2.9EG 2.92024-04-02
In Xpdf 4.05 (and earlier), a PDF object loop in an object stream leads to infinite recursion and a stack overflow.
- CVE-2024-3248LOWCVSS 2.9EG 2.92024-04-02
In Xpdf 4.05 (and earlier), a PDF object loop in the attachments leads to infinite recursion and a stack overflow.
- CVE-2024-32609HIGHCVSS 7.5EG 7.52024-05-14
HDF5 Library through 1.14.3 allows stack consumption in the function H5E_printf_stack in H5Eint.c.
- CVE-2024-34158HIGHCVSS 7.5EG 7.52024-09-06
Calling Parse on a "// +build" build tag line with deeply nested expressions can cause a panic due to stack exhaustion.
- CVE-2024-35886HIGHCVSS 7.8EG 7.82024-05-19
In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix infinite recursion in fib6_dump_done(). syzkaller reported infinite recursive calls of fib6_dump_done() during netlink socket destruction. [1] From the log, …
- CVE-2024-37973HIGHCVSS 8.8EG 8.82024-07-09
Secure Boot Security Feature Bypass Vulnerability
- CVE-2024-42369MEDIUMCVSS 4.1EG 4.12024-08-20
matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. A malicious homeserver can craft a room or room structure such that the predecessors form a cycle. The matrix-js-sdk's getRoomUpgradeHistory function will infin…
- CVE-2024-4340HIGHCVSS 7.5EG 7.52024-04-30
Passing a heavily nested list to sqlparse.parse() leads to a Denial of Service due to RecursionError.
- CVE-2024-43414HIGHCVSS 7.5EG 7.52024-08-27
Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Each team can own their slice of the graph independently, empowering them to deliver autonomously and incrementally. Instances of @apollo/query-pla…
- CVE-2024-44073HIGHCVSS 7.5EG 7.52024-08-19
The Miniscript (aka rust-miniscript) library before 12.2.0 for Rust allows stack consumption because it does not properly track tree depth.
- CVE-2024-44996MEDIUMCVSS 5.5EG 5.52024-09-04
In the Linux kernel, the following vulnerability has been resolved: vsock: fix recursive ->recvmsg calls After a vsock socket has been added to a BPF sockmap, its prot->recvmsg has been replaced with vsock_bpf_recvmsg(). Thus the followi…
- CVE-2024-4568LOWCVSS 2.9EG 2.92024-05-06
In Xpdf 4.05 (and earlier), a PDF object loop in the PDF resources leads to infinite recursion and a stack overflow.
- CVE-2024-47831MEDIUMCVSS 5.9EG 5.92024-10-14
Next.js is a React Framework for the Web. Cersions on the 10.x, 11.x, 12.x, 13.x, and 14.x branches before version 14.2.7 contain a vulnerability in the image optimization feature which allows for a potential Denial of Service (DoS) condit…
- CVE-2024-49363HIGHCVSS 7.4EG 7.42024-12-18
Misskey is an open source, federated social media platform. In affected versions FileServerService (media proxy) in github.com/misskey-dev/misskey 2024.10.1 or earlier did not detect proxy loops, which allows remote actors to execute a sel…
- CVE-2024-53090MEDIUMCVSS 5.5EG 5.52024-11-21
In the Linux kernel, the following vulnerability has been resolved: afs: Fix lock recursion afs_wake_up_async_call() can incur lock recursion. The problem is that it is called from AF_RXRPC whilst holding the ->notify_lock, but it tries…
- CVE-2024-54731MEDIUMCVSS 4.0EG 4.02025-01-08
cpdf through 2.8 allows stack consumption via a crafted PDF document.
- CVE-2024-57257LOWCVSS 2.0EG 2.02025-02-18
A stack consumption issue in sqfs_size in Das U-Boot before 2025.01-rc1 occurs via a crafted squashfs filesystem with deep symlink nesting.
- CVE-2024-57699HIGHCVSS 7.5EG 7.52025-02-05
A security issue was found in Netplex Json-smart 2.5.0 through 2.5.1. When loading a specially crafted JSON input, containing a large number of ’{’, a stack exhaustion can be trigger, which could allow an attacker to cause a Denial of …
- CVE-2024-58102MEDIUMCVSS 5.7EG 5.72025-03-11
An issue was discovered in Datalust Seq before 2024.3.13545. An insecure default parsing depth limit allows stack consumption when parsing user-supplied queries containing deeply nested expressions.
- CVE-2024-58103MEDIUMCVSS 5.8EG 5.82025-03-16
Square Wire before 5.2.0 does not enforce a recursion limit on nested groups in ByteArrayProtoReader32.kt and ProtoReader.kt.
- CVE-2024-58264LOWCVSS 3.2EG 3.22025-07-27
The serde-json-wasm crate before 1.0.1 for Rust allows stack consumption via deeply nested JSON data.
- CVE-2024-58370MEDIUMCVSS 6.5EG 6.52026-07-18
SurrealDB versions before 1.1.0 fail to enforce recursion depth limits when parsing nested SurrealQL statements including IF, RELATE, and attribute access idioms. Authorized attackers can submit queries with excessive nesting depth to caus…
- CVE-2024-5971HIGHCVSS 7.5EG 7.52024-07-08
A vulnerability was found in Undertow, where the chunked response hangs after the body was flushed. The response headers and body were sent but the client would continue waiting as Undertow does not send the expected 0\r\n termination of t…
- CVE-2024-7254HIGHCVSS 7.5EG 7.52024-09-19
Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGROUP tags can corrupted by exceeding the stack limit i.e. StackOverflow. Parsing nested groups as unknown fields with D…
- CVE-2024-7866MEDIUMCVSS 5.5EG 5.52024-08-15
In Xpdf 4.05 (and earlier), a PDF object loop in a pattern resource leads to infinite recursion and a stack overflow.
- CVE-2024-8176HIGHCVSS 7.5EG 7.52025-03-14
A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents. When parsing an XML document with deeply nested entity references, libexpat can be forced to recurse indef…
- CVE-2025-10728CRITICALCVSS 9.4EG 9.42025-10-03
When the module renders a Svg file that contains a <pattern> element, it might end up rendering it recursively leading to stack overflow DoS
- CVE-2025-11896LOWCVSS 2.1EG 2.12025-10-16
In Xpdf 4.05 (and earlier), a PDF object loop in a CMap, via the "UseCMap" entry, leads to infinite recursion and a stack overflow.
- CVE-2025-1492HIGHCVSS 7.8EG 7.82025-02-20
Bundle Protocol and CBOR dissector crashes in Wireshark 4.4.0 to 4.4.3 and 4.2.0 to 4.2.10 allows denial of service via packet injection or crafted capture file
- CVE-2025-1752HIGHCVSS 7.5EG 7.52025-05-10
A Denial of Service (DoS) vulnerability has been identified in the KnowledgeBaseWebReader class of the run-llama/llama_index project, affecting version ~ latest(v0.12.15). The vulnerability arises due to inappropriate secure coding measure…
- CVE-2025-20025MEDIUMCVSS 4.4EG 4.42025-08-12
Uncontrolled recursion for some TinyCBOR libraries maintained by Intel(R) before version 0.6.1 may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2025-20678HIGHCVSS 6.5EG 7.52025-06-02
In ims service, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privilege…
- CVE-2025-23325HIGHCVSS 7.5EG 7.52025-08-06
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause uncontrolled recursion through a specially crafted input. A successful exploit of this vulnerability might lead to denial of servic…
- CVE-2025-24302MEDIUMCVSS 6.7EG 6.72025-08-12
Uncontrolled recursion for some TinyCBOR libraries maintained by Intel(R) before version 0.6.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2025-30193HIGHCVSS 7.5EG 7.52025-05-20
In some circumstances, when DNSdist is configured to allow an unlimited number of queries on a single, incoming TCP connection from a client, an attacker can cause a denial of service by crafting a TCP exchange that triggers an exhaustion …
- CVE-2025-32387MEDIUMCVSS 6.5EG 6.52025-04-09
Helm is a package manager for Charts for Kubernetes. A JSON Schema file within a chart can be crafted with a deeply nested chain of references, leading to parser recursion that can exceed the stack size limit and trigger a stack overflow. …
- CVE-2025-33096MEDIUMCVSS 6.5EG 6.52025-10-12
IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user to cause a denial of service by uploading specially crafted files using uncontrolled recursion.
- CVE-2025-36001MEDIUMCVSS 6.5EG 6.52026-01-30
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow an authenticated user to cause a denial of service using a specially crafted SQL statement including XML that performs uncont…
Map vulnerabilities like CWE-674 to your infrastructure
EchelonGraph correlates every CVE — across CWE-674 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →