CWE-674

Uncontrolled Recursion

Parent: CWE-834 - Excessive Iteration

The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

474 vulnerabilities with CWE-674
CVE-2026-25971 MEDIUM
ImageMagick <7.1.2-15/6.9.13-40 - Memory Corruption
CVSS 6.2
CVE-2026-2887 LOW
aardappel lobster <2025.4 - Memory Corruption
CVSS 3.3
CVE-2026-27014 MEDIUM
NanaZip 5.0.1252.0-6.0.1630.0 - DoS
CVSS 5.5
CVE-2026-2641 LOW
universal-ctags ctags <= 6.2.1 - Uncontrolled Recursion in V Language Parser
CVSS 3.3
CVE-2026-1849 MEDIUM
MongoDB 7.0.0-7.0.28 - Denial of Service via Deeply Nested Document Evaluation
CVSS 6.5
CVE-2026-23066 HIGH
Linux Kernel 4.11.0-6.18.8 - Use-After-Free in rxrpc_recvmsg() Requeue Logic
CVSS 7.8
CVE-2026-22260 HIGH
Suricata 8.0.0-8.0.3 - Denial of Service via Stack Overflow
CVSS 7.5
CVE-2026-24401 MEDIUM
avahi < 0.9 - Denial of Service via Recursive CNAME Record
CVSS 6.5
CVE-2026-0994 HIGH
Protobuf - Denial of Service via Recursion Depth Bypass in Any Message Parsing
CVSS 7.5
CVE-2026-0990 MEDIUM
Red Hat Enterprise Linux 6-10 - Denial of Service via XML Catalog Delegate URI Recursion
CVSS 5.9
CVE-2026-0989 LOW
Red Hat Enterprise Linux - Denial of Service via RelaxNG Parser Recursion
CVSS 3.7
CVE-2026-21500 MEDIUM
iccdev < 2.3.1.2 - Stack Overflow in XML Calculator Macro Expansion
CVSS 5.5
CVE-2025-71393 MEDIUM
SurrealDB before 2.2.2 Memory Exhaustion via Nested Functions
CVE-2025-71382 MEDIUM
MuPDF < 1.27.0-rc1 Stack Exhaustion DoS via EPUB CSS Rendering
CVSS 6.5
CVE-2025-7010 MEDIUM
Avast antivirus stack overflow when scanning a malformed PDF file
CVSS 5.5
CVE-2025-7005 MEDIUM
Avast antivirus infinite recursion when scanning a malformed PE file
CVSS 5.5
CVE-2025-65519 MEDIUM
mayswind ezbookkeeping <=1.2.0 - DoS
CVSS 6.5
CVE-2025-70957 HIGH
TON Lite Server < 2024.09 - Denial of Service via Malicious Continuation Object Injection
CVSS 7.5
CVE-2025-70955 HIGH
TON TVM <2024.10 - Memory Corruption
CVSS 7.5
CVE-2025-36001 MEDIUM
IBM Db2 11.5.0-11.5.9 and 12.1.0-12.1.3 - Authenticated Denial of Service via XML Recursion
CVSS 6.5
CVE-2025-55095 MEDIUM
UX Host Class Storage - Buffer Overflow
CVSS 4.2
CVE-2025-50537 MEDIUM
eslint < 9.26.0 - Denial of Service via Circular Reference Serialization
CVSS 5.5
CVE-2025-68950 MEDIUM
ImageMagick < 7.1.2-12 - Denial of Service via Circular MVG Reference
CVSS 4.0
CVE-2025-68618 MEDIUM
ImageMagick < 7.1.2-12 - Denial of Service via Malicious SVG File
CVSS 5.3
CVE-2025-67899 LOW
uriparser <= 0.9.9 - Denial of Service via Unbounded Recursion in ParseMustBeSegmentNzNc
CVSS 2.9
Details
Vulnerabilities 474