CWE-674

Uncontrolled Recursion

Parent: CWE-834 - Excessive Iteration

The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

474 vulnerabilities with CWE-674
CVE-2026-18140 HIGH
aws-smithy-json < 0.62.7 - Recursive JSON Denial of Service
CVSS 7.5
CVE-2026-67194 MEDIUM
Courier IMAP < 6.0.1 Mail Server < 2.0.2 Stack Overflow DoS via Nested SEARCH Queries
CVSS 6.5
CVE-2026-67215 HIGH
cJSON JSON Patch copy/add Uncontrolled Recursion Stack Exhaustion
CVSS 7.5
CVE-2026-58178 HIGH
Apache Traffic Server: ESI plugin allows uncontrolled recursion and server-side request forgery
CVSS 7.5
CVE-2026-16192 HIGH
IBM WebSphere Application Server Liberty is affected by a denial of service
CVSS 7.1
CVE-2026-66920 HIGH
Pivotick - Stack Exhaustion Denial of Service via Deep or Cyclic Graph Data
CVE-2026-58227 HIGH
TLS/DTLS denial of service via unbounded recursion on cross-signed peer certificate chain
CVE-2026-17501 MEDIUM
ggml-org llama.cpp JSON-Schema-to-GBNF Conversion json-schema-to-grammar.cpp transform allocation of resources
CVSS 5.3
CVE-2026-63144 MEDIUM
Uncontrolled Recursion in Elasticsearch Leading to Denial of Service
CVSS 6.5
CVE-2026-64194 HIGH
Net::DNS <= 1.55 - Denial of Service via Compression Pointer Recursion
CVSS 7.5
CVE-2026-63760 HIGH
SurrealDB before 3.1.0 Denial of Service via JSON Parser
CVSS 7.5
CVE-2026-63759 MEDIUM
SurrealDB before 3.1.0 Denial of Service nested type annotations
CVSS 6.5
CVE-2026-63737 MEDIUM
SurrealDB before 3.1.5 Denial of Service via deep operator chains
CVSS 6.5
CVE-2026-53395 HIGH
nfsd: fix dead ACL conflict guard in nfsd4_create
CVSS 7.5
CVE-2026-47180 MEDIUM
Zeroconf: Unbounded recursion in DNS compression-pointer decoder allows LAN-local denial of service
CVSS 6.5
CVE-2026-38755 LOW
BusyBox 1.38.0 - Denial of Service via Heap Overflow in evalcommand Function
CVSS 2.9
CVE-2026-38752 LOW
BusyBox - Denial of Service via Crafted AWK Script in evaluate() Function
CVSS 2.9
CVE-2026-45133 HIGH
Symfony: [Yaml] Harden the parser when handling untrusted input
CVSS 7.5
CVE-2026-40007 HIGH
Apache IoTDB: Unauthenticated unbounded recursion in IoTDB AirGap receiver's E-language prefix parser causes per-connection StackOverflowError
CVSS 7.5
CVE-2026-59927 MEDIUM
Mistune < 3.3.0 Include Directive - Uncontrolled Recursion Denial of Service
CVSS 5.3
CVE-2026-14803 MEDIUM
Mojo::JSON < 9.47 - Memory Exhaustion via Unbounded Recursion
CVSS 6.5
CVE-2026-38970 HIGH
pdfcpu <= 0.11.1 - Denial of Service via Uncontrolled Recursion in Nested PDF Object Parser
CVSS 7.5
CVE-2026-55594 MEDIUM
ImageMagick: Stack Overflow in MVG decoder due to missing depth check.
CVSS 5.3
CVE-2026-56148 MEDIUM
Uncontrolled Recursion in Elasticsearch Leading to Denial of Service
CVSS 6.5
CVE-2026-53329 HIGH
drm/amd/display: Use krealloc_array() in dal_vector_reserve()
CVSS 7.0
Details
Vulnerabilities 474