CWE-674

Uncontrolled Recursion

Parent: CWE-834 - Excessive Iteration

The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

430 vulnerabilities with CWE-674
CVE-2025-24302 MEDIUM
TinyCBOR <0.6.1 - Privilege Escalation
CVSS 6.7
CVE-2025-20025 MEDIUM
TinyCBOR libraries maintained by Intel(R) < 0.6.1 - Authenticated Denial of Service via Uncontrolled Recursion
CVSS 4.4
CVE-2025-8732 LOW
libxml2 <2.14.5 - Uncontrolled Recursion
CVSS 3.3
CVE-2025-23325 HIGH
NVIDIA Triton Inference Server < 25.05 - Denial of Service via Uncontrolled Recursion
CVSS 7.5
CVE-2025-46206 MEDIUM
Artifex MuPDF < 1.25.6 - Denial of Service via Infinite Recursion in mutool clean
CVSS 6.5
CVE-2025-50420 MEDIUM
freedesktop poppler <v25.04.0 - DoS
CVSS 6.5
CVE-2025-38493 MEDIUM
Linux Kernel 6.6-6.6.99, 6.7-6.12.39, 6.13-6.15.7 - Denial of Service via Uncontrolled Recursion in timerlat_dump_stack
CVSS 5.5
CVE-2025-38459 HIGH
Linux Kernel <=6.15.7 - Uncontrolled Recursion via ATMARP_MKIP ioctl
CVSS 7.8
CVE-2025-48924 MEDIUM
Apache Commons Lang <3.18.0 - Uncontrolled Recursion
CVSS 5.3
CVE-2025-53864 MEDIUM
Connect2id Nimbus JOSE + JWT <10.0.2-9.37.4 - DoS
CVSS 5.8
CVE-2025-38315 MEDIUM
Linux Kernel - Stack Buffer Overflow in Bluetooth btintel EFI Variable Handling
CVSS 5.5
CVE-2025-5472 MEDIUM
run-llama/llama_index <0.12.28 - Buffer Overflow
CVSS 6.5
CVE-2025-53605 MEDIUM
protobuf < 3.7.2 - Uncontrolled Recursion in CodedInputStream Group Parsing
CVSS 5.9
CVE-2025-6710 HIGH
MongoDB 6.0.0-6.0.20 - Authenticated Denial of Service via JSON Parsing Recursion
CVSS 7.5
CVE-2025-4565 MEDIUM
protobuf-python < 4.25.8 - Denial of Service via Recursive Protocol Buffers Parsing
CVSS 5.3
CVE-2025-20678 MEDIUM
MediaTek LR12A, LR13, NR15, NR16, NR17, NR17R - Remote Denial of Service via Rogue Base Station
CVSS 6.5
CVE-2025-30193 HIGH
DNSdist < 1.9.10 - Denial of Service via Unlimited TCP Queries
CVSS 7.5
CVE-2025-1752 HIGH
run-llama/llama_index ~ latest(v0.12.15 - DoS
CVSS 7.5
CVE-2025-37851 MEDIUM
Linux Kernel - Buffer Overflow in fbdev omapfb via dispc_ovl_setup
CVSS 5.5
CVE-2025-43708 LOW
VisiCut 2.1 - Denial of Service via Nested XML Set Elements
CVSS 3.3
CVE-2025-32387 MEDIUM
Helm < 3.17.3 - Stack-based Buffer Overflow via Deeply Nested JSON Schema References
CVSS 6.5
CVE-2025-1492 HIGH
Wireshark 4.2.0-4.2.10 and 4.4.0-4.4.3 - Denial of Service via Bundle Protocol and CBOR Dissector
CVSS 7.8
CVE-2024-58264 LOW
serde-json-wasm < 1.0.1 - Uncontrolled Recursion via Deeply Nested JSON Data
CVSS 3.2
CVE-2024-12910 MEDIUM
Llamaindex < 0.12.9 - Denial of Service
CVSS 5.9
CVE-2024-58103 MEDIUM
Square Wire <5.2.0 - Info Disclosure
CVSS 5.8
Details
Vulnerabilities 430