The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.
386 vulnerabilities with CWE-674
CVE-2026-7164
pf can overflow the stack parsing crafted SCTP packets
CVE-2026-6527
MEDIUM
Uncontrolled Recursion in Wireshark
CVSS 5.5
CVE-2026-5409
MEDIUM
Uncontrolled Recursion in Wireshark
CVSS 5.5
CVE-2026-5408
MEDIUM
Uncontrolled Recursion in Wireshark
CVSS 5.5
CVE-2026-5406
MEDIUM
Uncontrolled Recursion in Wireshark
CVSS 5.5
CVE-2026-5401
MEDIUM
Uncontrolled Recursion in Wireshark
CVSS 5.5
CVE-2026-5299
MEDIUM
Uncontrolled Recursion in Wireshark
CVSS 5.5
CVE-2026-41636
HIGH
Apache Thrift: Node.js skip() recursion
CVSS 7.5
CVE-2026-41606
MEDIUM
Apache Thrift: c_glib dispatch stack overflow
CVSS 5.3
CVE-2026-42039
HIGH
Axios: unbounded recursion in toFormData causes DoS via deeply nested request data
CVSS 7.5
CVE-2026-41680
HIGH
Marked: OOM Denial of Service via Infinite Recursion in marked Tokenizer
CVSS 7.5
CVE-2026-6862
MEDIUM
Efivar: efivar: denial of service due to stack overflow in device path node parsing
CVSS 5.5
CVE-2026-40879
HIGH
Nest: DoS via Recursive handleData in JsonSocket (TCP Transport)
CVSS 7.5
CVE-2026-39396
LOW
OpenBao has Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)
CVSS 3.1
CVE-2026-40324
CRITICAL
Hot Chocolate's Utf8GraphQLParser has Stack Overflow via Deeply Nested GraphQL Documents
CVSS 9.1
CVE-2026-33947
MEDIUM
jq: Unbounded Recursion in jv_setpath(), jv_getpath() and delpaths_sorted()
CVSS 6.2
CVE-2026-33908
HIGH
ImageMagick is vulnerable to Stack Overflow in DestroyXMLTree()
CVSS 7.5
CVE-2026-33902
MEDIUM
ImageMagick: Stack Overflow via Recursive FX Expression Parsing
CVSS 5.5
CVE-2026-39376
HIGH
FastFeedParser has an infinite redirect loop DoS via meta-refresh chain
CVSS 7.5
CVE-2026-34211
HIGH
SandboxJS: Stack overflow DoS via deeply nested expressions in recursive descent parser
CVSS 7.5
CVE-2026-3778
MEDIUM
Stack exhaustion caused by cyclic references in Foxit PDF Editor/Reader
CVSS 6.2
CVE-2026-34536
MEDIUM
iccDEV: SO in SIccCalcOp::ArgsUsed()
CVSS 6.2
CVE-2026-33532
MEDIUM
yaml is vulnerable to Stack Overflow via deeply nested YAML collections
CVSS 4.3
CVE-2026-4833
LOW
Orc discount Markdown markdown.c compile recursion
CVSS 3.3
CVE-2026-33508
HIGH
Parse Server: LiveQuery subscription query depth bypass
CVSS 7.5
Details
Vulnerabilities
386