The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.
474 vulnerabilities with CWE-674
CVE-2026-18140
HIGH
aws-smithy-json < 0.62.7 - Recursive JSON Denial of Service
CVSS 7.5
CVE-2026-67194
MEDIUM
Courier IMAP < 6.0.1 Mail Server < 2.0.2 Stack Overflow DoS via Nested SEARCH Queries
CVSS 6.5
CVE-2026-67215
HIGH
cJSON JSON Patch copy/add Uncontrolled Recursion Stack Exhaustion
CVSS 7.5
CVE-2026-58178
HIGH
Apache Traffic Server: ESI plugin allows uncontrolled recursion and server-side request forgery
CVSS 7.5
CVE-2026-16192
HIGH
IBM WebSphere Application Server Liberty is affected by a denial of service
CVSS 7.1
CVE-2026-66920
HIGH
Pivotick - Stack Exhaustion Denial of Service via Deep or Cyclic Graph Data
CVE-2026-58227
HIGH
TLS/DTLS denial of service via unbounded recursion on cross-signed peer certificate chain
CVE-2026-17501
MEDIUM
ggml-org llama.cpp JSON-Schema-to-GBNF Conversion json-schema-to-grammar.cpp transform allocation of resources
CVSS 5.3
CVE-2026-63144
MEDIUM
Uncontrolled Recursion in Elasticsearch Leading to Denial of Service
CVSS 6.5
CVE-2026-64194
HIGH
Net::DNS <= 1.55 - Denial of Service via Compression Pointer Recursion
CVSS 7.5
CVE-2026-63760
HIGH
SurrealDB before 3.1.0 Denial of Service via JSON Parser
CVSS 7.5
CVE-2026-63759
MEDIUM
SurrealDB before 3.1.0 Denial of Service nested type annotations
CVSS 6.5
CVE-2026-63737
MEDIUM
SurrealDB before 3.1.5 Denial of Service via deep operator chains
CVSS 6.5
CVE-2026-53395
HIGH
nfsd: fix dead ACL conflict guard in nfsd4_create
CVSS 7.5
CVE-2026-47180
MEDIUM
Zeroconf: Unbounded recursion in DNS compression-pointer decoder allows LAN-local denial of service
CVSS 6.5
CVE-2026-38755
LOW
BusyBox 1.38.0 - Denial of Service via Heap Overflow in evalcommand Function
CVSS 2.9
CVE-2026-38752
LOW
BusyBox - Denial of Service via Crafted AWK Script in evaluate() Function
CVSS 2.9
CVE-2026-45133
HIGH
Symfony: [Yaml] Harden the parser when handling untrusted input
CVSS 7.5
CVE-2026-40007
HIGH
Apache IoTDB: Unauthenticated unbounded recursion in IoTDB AirGap receiver's E-language prefix parser causes per-connection StackOverflowError
CVSS 7.5
CVE-2026-59927
MEDIUM
Mistune < 3.3.0 Include Directive - Uncontrolled Recursion Denial of Service
CVSS 5.3
CVE-2026-14803
MEDIUM
Mojo::JSON < 9.47 - Memory Exhaustion via Unbounded Recursion
CVSS 6.5
CVE-2026-38970
HIGH
pdfcpu <= 0.11.1 - Denial of Service via Uncontrolled Recursion in Nested PDF Object Parser
CVSS 7.5
CVE-2026-55594
MEDIUM
ImageMagick: Stack Overflow in MVG decoder due to missing depth check.
CVSS 5.3
CVE-2026-56148
MEDIUM
Uncontrolled Recursion in Elasticsearch Leading to Denial of Service
CVSS 6.5
CVE-2026-53329
HIGH
drm/amd/display: Use krealloc_array() in dal_vector_reserve()
CVSS 7.0
Details
Vulnerabilities
474