The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.
430 vulnerabilities with CWE-674
CVE-2026-4870
HIGH
IBM Qiskit SDK 0.43.0-2.5.0 - Parser Recursion Denial of Service
CVSS 7.5
CVE-2026-48734
MEDIUM
ImageMagick: Stack Overflow in MVG decoder
CVSS 5.5
CVE-2026-46557
MEDIUM
ImageMagick: Stack overflow in fx operation
CVSS 6.2
CVE-2026-46689
HIGH
Kanidm: Unauthenticated process abort via SCIM filter stack exhaustion
CVE-2026-45664
MEDIUM
ImageMagick: Policy Bypass in MNG coder could
CVSS 5.3
CVE-2026-9740
HIGH
Unbounded recursion in BSONColumn interleaved-reference causes pre-auth stack overflow
CVSS 7.5
CVE-2026-46373
HIGH
SQLFluff: Recursive Stack Overflow in Parser
CVSS 7.5
CVE-2026-49847
HIGH
FreeSWITCH: Stack overflow in bundled cJSON parser via deeply nested JSON
CVSS 7.5
CVE-2026-49941
HIGH
Net::CIDR::Set versions through 0.20 for Perl did not validate IP addresses
CVSS 7.5
CVE-2026-47706
MEDIUM
Strawberry GraphQL 0.71.0-0.315.6 Fragments - Denial of Service
CVSS 5.3
CVE-2026-47320
MEDIUM
Samsung Open Source Rlottie - Uncontrolled Recursion
CVSS 6.1
CVE-2026-47306
MEDIUM
Samsung Open Source Rlottie - Uncontrolled Recursion
CVSS 6.1
CVE-2026-8936
HIGH
Unbounded recursion in grpcfuse kernel module allows container to crash Docker Desktop VM
CVE-2026-40989
MEDIUM
Spring Cloud Function DoS via Infinite Recursion in Routing Layer
CVSS 5.7
CVE-2026-44740
MEDIUM
go-billy < 5.9.0 - Symlink Resolution Resource Exhaustion
CVSS 6.5
CVE-2026-46149
HIGH
scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show()
CVSS 7.1
CVE-2026-42328
MEDIUM
go-ipld-prime: DAG-CBOR and DAG-JSON decoders unbounded recursion depth
CVSS 6.2
CVE-2026-6936
MEDIUM
IBM i is Affected by a Denial of Service Vulnerability []
CVSS 6.5
CVE-2026-44844
MEDIUM
eml_parser: Recursion DoS via nested message/rfc822 attachments
CVE-2026-7453
MEDIUM
WRL File Parsing Memory Exhaustion in Autodesk 3ds Max
CVSS 5.5
CVE-2026-9358
MEDIUM
postcss AST Serialization container.js toString recursion
CVSS 4.3
CVE-2026-47317
MEDIUM
Samsung Open Source Escargot 590345cc6258317c5da850d846ce6baaf2afc2d3 - Uncontrolled Recursion
CVSS 5.5
CVE-2026-47309
MEDIUM
Samsung Escargot 590345cc6258317c5da850d846ce6baaf2afc2d3 - Uncontrolled Recursion via Oversized Payloads
CVSS 5.5
CVE-2026-6811
MEDIUM
MongoDB PHP Driver 1.21.5-2.1.8 - Denial of Service via Deeply Nested BSON Document Processing
CVSS 5.9
CVE-2026-41935
HIGH
Vvveb < 1.0.8.3 Uncontrolled Recursion Denial of Service
CVSS 7.1
Details
Vulnerabilities
430