CWE-674

Uncontrolled Recursion

Parent: CWE-834 - Excessive Iteration

The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

474 vulnerabilities with CWE-674
CVE-2026-49451 HIGH
Microsoft.OpenAPI: Circular schema references may terminate OpenAPI parsing
CVSS 7.5
CVE-2026-57081 HIGH
Net::BitTorrent <= 2.0.1 - Bencode Memory Exhaustion
CVSS 7.5
CVE-2026-54888 MEDIUM
Uncontrolled recursion over deeply nested Markdown crashes the BEAM in mdex
CVE-2026-13757 MEDIUM
P11-kit: stack exhaustion via unbounded recursion in rpc attribute parsing
CVSS 6.2
CVE-2026-53288 MEDIUM
arm64: Reserve an extra page for early kernel mapping
CVSS 5.5
CVE-2026-47770 MEDIUM
jq: stack overflow in deep structural equality
CVSS 5.5
CVE-2026-53267 HIGH
netfilter: nft_ct: bail out on template ct in get eval
CVSS 7.8
CVE-2026-53202 HIGH
accel/ivpu: Fix signed integer truncation in IPC receive
CVSS 7.8
CVE-2026-54297 HIGH
Faraday NestedParamsEncoder < 1.10.6/2.14.3 - Stack Exhaustion DoS
CVSS 7.5
CVE-2026-48513 HIGH
MessagePack-CSharp: DynamicUnionResolver generated deserializers miss depth enforcement
CVSS 7.5
CVE-2026-48512 HIGH
MessagePack-CSharp: JSON conversion APIs can recurse without consistent depth enforcement
CVSS 7.5
CVE-2026-48506 HIGH
MessagePack-CSharp: MessagePackReader.Skip can recurse without enforcing maximum object graph depth
CVSS 7.5
CVE-2026-48502 HIGH
MessagePack-CSharp ReadDateTime - Stack Overflow Denial of Service
CVSS 7.5
CVE-2026-54269 MEDIUM
protobufjs: Schema-derived names can shadow runtime-significant properties
CVSS 5.3
CVE-2026-48712 HIGH
protobufjs: Denial of service through unbounded Any expansion during JSON conversion
CVSS 7.5
CVE-2026-4870 HIGH
IBM Qiskit SDK 0.43.0-2.5.0 - Parser Recursion Denial of Service
CVSS 7.5
CVE-2026-48734 MEDIUM
ImageMagick: Stack Overflow in MVG decoder
CVSS 5.5
CVE-2026-46557 MEDIUM
ImageMagick: Stack overflow in fx operation
CVSS 6.2
CVE-2026-46689 HIGH
Kanidm: Unauthenticated process abort via SCIM filter stack exhaustion
CVE-2026-45664 MEDIUM
ImageMagick: Policy Bypass in MNG coder could
CVSS 5.3
CVE-2026-9740 HIGH
Unbounded recursion in BSONColumn interleaved-reference causes pre-auth stack overflow
CVSS 7.5
CVE-2026-46373 HIGH
SQLFluff: Recursive Stack Overflow in Parser
CVSS 7.5
CVE-2026-49847 HIGH
FreeSWITCH: Stack overflow in bundled cJSON parser via deeply nested JSON
CVSS 7.5
CVE-2026-49941 HIGH
Net::CIDR::Set versions through 0.20 for Perl did not validate IP addresses
CVSS 7.5
CVE-2026-47706 MEDIUM
Strawberry GraphQL 0.71.0-0.315.6 Fragments - Denial of Service
CVSS 5.3
Details
Vulnerabilities 474