CWE-674

Uncontrolled Recursion

Parent: CWE-834 - Excessive Iteration

The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

474 vulnerabilities with CWE-674
CVE-2026-40612 MEDIUM
jq: Stack overflow via unbounded recursion in jv_contains
CVSS 5.5
CVE-2026-41311 HIGH
LiquidJS is vulnerable to Denial of Service via circular block reference in layout
CVSS 7.5
CVE-2026-41673 HIGH
xmldom: Denial of service via uncontrolled recursion in XML serialization
CVSS 7.5
CVE-2026-43185 CRITICAL
ksmbd: fix signededness bug in smb_direct_prepare_negotiation()
CVSS 9.8
CVE-2026-43080 MEDIUM
l2tp: Drop large packets with UDP encap
CVSS 5.5
CVE-2026-44028 HIGH
Nix 2.24.4-2.34.6 and Lix 2.93.0-2.95.1 - Unauthenticated Remote Code Execution via NAR Parser Uncontrolled Recursion
CVSS 7.5
CVE-2026-7164 HIGH
FreeBSD pf - SCTP Packet Stack Overflow Denial of Service
CVSS 7.5
CVE-2026-6527 MEDIUM
Uncontrolled Recursion in Wireshark
CVSS 5.5
CVE-2026-5409 MEDIUM
Uncontrolled Recursion in Wireshark
CVSS 5.5
CVE-2026-5408 MEDIUM
Uncontrolled Recursion in Wireshark
CVSS 5.5
CVE-2026-5406 MEDIUM
Uncontrolled Recursion in Wireshark
CVSS 5.5
CVE-2026-5401 MEDIUM
Uncontrolled Recursion in Wireshark
CVSS 5.5
CVE-2026-5299 MEDIUM
Uncontrolled Recursion in Wireshark
CVSS 5.5
CVE-2026-41636 HIGH
Apache Thrift: Node.js skip() recursion
CVSS 7.5
CVE-2026-41606 MEDIUM
Apache Thrift: c_glib dispatch stack overflow
CVSS 5.3
CVE-2026-42039 HIGH
Axios: unbounded recursion in toFormData causes DoS via deeply nested request data
CVSS 7.5
CVE-2026-41680 HIGH
Marked: OOM Denial of Service via Infinite Recursion in marked Tokenizer
CVSS 7.5
CVE-2026-6862 MEDIUM
Efivar: efivar: denial of service due to stack overflow in device path node parsing
CVSS 5.5
CVE-2026-40879 HIGH
Nest: DoS via Recursive handleData in JsonSocket (TCP Transport)
CVSS 7.5
CVE-2026-39396 LOW
OpenBao has Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)
CVSS 3.1
CVE-2026-40324 CRITICAL
Hot Chocolate's Utf8GraphQLParser has Stack Overflow via Deeply Nested GraphQL Documents
CVSS 9.1
CVE-2026-33947 MEDIUM
jq: Unbounded Recursion in jv_setpath(), jv_getpath() and delpaths_sorted()
CVSS 6.2
CVE-2026-33908 HIGH
ImageMagick is vulnerable to Stack Overflow in DestroyXMLTree()
CVSS 7.5
CVE-2026-33902 MEDIUM
ImageMagick: Stack Overflow via Recursive FX Expression Parsing
CVSS 5.5
CVE-2026-39376 HIGH
FastFeedParser <0.5.10 Meta-Refresh Redirects - Denial of Service
CVSS 7.5
Details
Vulnerabilities 474