The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.
474 vulnerabilities with CWE-674
CVE-2026-49451
HIGH
Microsoft.OpenAPI: Circular schema references may terminate OpenAPI parsing
CVSS 7.5
CVE-2026-57081
HIGH
Net::BitTorrent <= 2.0.1 - Bencode Memory Exhaustion
CVSS 7.5
CVE-2026-54888
MEDIUM
Uncontrolled recursion over deeply nested Markdown crashes the BEAM in mdex
CVE-2026-13757
MEDIUM
P11-kit: stack exhaustion via unbounded recursion in rpc attribute parsing
CVSS 6.2
CVE-2026-53288
MEDIUM
arm64: Reserve an extra page for early kernel mapping
CVSS 5.5
CVE-2026-47770
MEDIUM
jq: stack overflow in deep structural equality
CVSS 5.5
CVE-2026-53267
HIGH
netfilter: nft_ct: bail out on template ct in get eval
CVSS 7.8
CVE-2026-53202
HIGH
accel/ivpu: Fix signed integer truncation in IPC receive
CVSS 7.8
CVE-2026-54297
HIGH
Faraday NestedParamsEncoder < 1.10.6/2.14.3 - Stack Exhaustion DoS
CVSS 7.5
CVE-2026-48513
HIGH
MessagePack-CSharp: DynamicUnionResolver generated deserializers miss depth enforcement
CVSS 7.5
CVE-2026-48512
HIGH
MessagePack-CSharp: JSON conversion APIs can recurse without consistent depth enforcement
CVSS 7.5
CVE-2026-48506
HIGH
MessagePack-CSharp: MessagePackReader.Skip can recurse without enforcing maximum object graph depth
CVSS 7.5
CVE-2026-48502
HIGH
MessagePack-CSharp ReadDateTime - Stack Overflow Denial of Service
CVSS 7.5
CVE-2026-54269
MEDIUM
protobufjs: Schema-derived names can shadow runtime-significant properties
CVSS 5.3
CVE-2026-48712
HIGH
protobufjs: Denial of service through unbounded Any expansion during JSON conversion
CVSS 7.5
CVE-2026-4870
HIGH
IBM Qiskit SDK 0.43.0-2.5.0 - Parser Recursion Denial of Service
CVSS 7.5
CVE-2026-48734
MEDIUM
ImageMagick: Stack Overflow in MVG decoder
CVSS 5.5
CVE-2026-46557
MEDIUM
ImageMagick: Stack overflow in fx operation
CVSS 6.2
CVE-2026-46689
HIGH
Kanidm: Unauthenticated process abort via SCIM filter stack exhaustion
CVE-2026-45664
MEDIUM
ImageMagick: Policy Bypass in MNG coder could
CVSS 5.3
CVE-2026-9740
HIGH
Unbounded recursion in BSONColumn interleaved-reference causes pre-auth stack overflow
CVSS 7.5
CVE-2026-46373
HIGH
SQLFluff: Recursive Stack Overflow in Parser
CVSS 7.5
CVE-2026-49847
HIGH
FreeSWITCH: Stack overflow in bundled cJSON parser via deeply nested JSON
CVSS 7.5
CVE-2026-49941
HIGH
Net::CIDR::Set versions through 0.20 for Perl did not validate IP addresses
CVSS 7.5
CVE-2026-47706
MEDIUM
Strawberry GraphQL 0.71.0-0.315.6 Fragments - Denial of Service
CVSS 5.3
Details
Vulnerabilities
474