CWE-674

Uncontrolled Recursion

Parent: CWE-834 - Excessive Iteration

The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

474 vulnerabilities with CWE-674
CVE-2026-34211 HIGH
SandboxJS: Stack overflow DoS via deeply nested expressions in recursive descent parser
CVSS 7.5
CVE-2026-3778 MEDIUM
Stack exhaustion caused by cyclic references in Foxit PDF Editor/Reader
CVSS 6.2
CVE-2026-34536 MEDIUM
iccDEV: SO in SIccCalcOp::ArgsUsed()
CVSS 6.2
CVE-2026-33532 MEDIUM
yaml is vulnerable to Stack Overflow via deeply nested YAML collections
CVSS 4.3
CVE-2026-4833 LOW
Orc discount Markdown markdown.c compile recursion
CVSS 3.3
CVE-2026-23292 MEDIUM
scsi: target: Fix recursive locking in __configfs_open_file()
CVSS 5.5
CVE-2026-33508 HIGH
Parse Server: LiveQuery subscription query depth bypass
CVSS 7.5
CVE-2026-33498 HIGH
Parse Server: Query condition depth bypass via pre-validation transform pipeline
CVSS 7.5
CVE-2026-33320 MEDIUM
Dasel has unbounded YAML alias expansion in dasel leads to CPU/memory denial of service
CVSS 6.2
CVE-2026-26209 HIGH
cbor2 < 5.9.0 - Denial of Service via Deeply Nested CBOR Structures
CVSS 7.5
CVE-2026-23276 MEDIUM
net: add xmit recursion limit to tunnel xmit functions
CVSS 5.5
CVE-2026-32933 HIGH
AutoMapper Vulnerable to Denial of Service (DoS) via Uncontrolled Recursion
CVSS 7.5
CVE-2026-32944 HIGH
Parse Server crash via deeply nested query condition operators
CVSS 7.5
CVE-2026-30922 HIGH
pyasn1 Vulnerable to Denial of Service via Unbounded Recursion
CVSS 7.5
CVE-2026-4224 HIGH
Stack overflow parsing XML with deeply nested DTD content models
CVSS 7.5
CVE-2026-31899 HIGH
CairoSVG < 2.9.0 - Denial of Service via Recursive <use> Element Amplification
CVSS 7.5
CVE-2026-32141 HIGH
flatted < 3.4.0 - Denial of Service via Uncontrolled Recursion in parse() Function
CVSS 7.5
CVE-2026-1069 HIGH
GitLab 18.9.0-18.9.1 - Unauthenticated Denial of Service via GraphQL Request
CVSS 7.5
CVE-2026-30980 MEDIUM
iccdev < 2.3.1.5 - Denial of Service via Stack Overflow in CIccBasicStructFactory::CreateStruct()
CVSS 5.5
CVE-2026-29076 MEDIUM
cpp-httplib < 0.37.0 - Denial of Service via RFC 5987 Filename Regex Backtracking
CVSS 5.9
CVE-2026-25048 HIGH
xgrammar <0.1.32 - Memory Corruption
CVSS 7.5
CVE-2026-3520 HIGH
Multer < 2.1.1 - Denial of Service via Malformed Request
CVSS 7.5
CVE-2026-3388 LOW
Squirrel up to 3.2 - Memory Corruption
CVSS 3.3
CVE-2026-3385 LOW
wren-lang wren <=0.4.0 - Memory Corruption
CVSS 3.3
CVE-2026-3384 LOW
ChaiScript < 6.1.0 - Uncontrolled Recursion in AST_Node_Impl Eval Function
CVSS 3.3
Details
Vulnerabilities 474