The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.
474 vulnerabilities with CWE-674
CVE-2025-38459
HIGH
Linux Kernel <=6.15.7 - Uncontrolled Recursion via ATMARP_MKIP ioctl
CVSS 7.8
CVE-2025-48924
MEDIUM
Apache Commons Lang <3.18.0 - Uncontrolled Recursion
CVSS 5.3
CVE-2025-53864
MEDIUM
Connect2id Nimbus JOSE + JWT <10.0.2-9.37.4 - DoS
CVSS 5.8
CVE-2025-38315
MEDIUM
Linux Kernel - Stack Buffer Overflow in Bluetooth btintel EFI Variable Handling
CVSS 5.5
CVE-2025-5472
MEDIUM
run-llama/llama_index <0.12.28 - Buffer Overflow
CVSS 6.5
CVE-2025-53605
MEDIUM
protobuf < 3.7.2 - Uncontrolled Recursion in CodedInputStream Group Parsing
CVSS 5.9
CVE-2025-6710
HIGH
MongoDB 6.0.0-6.0.20 - Authenticated Denial of Service via JSON Parsing Recursion
CVSS 7.5
CVE-2025-4565
MEDIUM
protobuf-python < 4.25.8 - Denial of Service via Recursive Protocol Buffers Parsing
CVSS 5.3
CVE-2025-20678
MEDIUM
MediaTek LR12A, LR13, NR15, NR16, NR17, NR17R - Remote Denial of Service via Rogue Base Station
CVSS 6.5
CVE-2025-30193
HIGH
DNSdist < 1.9.10 - Denial of Service via Unlimited TCP Queries
CVSS 7.5
CVE-2025-1752
HIGH
run-llama/llama_index ~ latest(v0.12.15 - DoS
CVSS 7.5
CVE-2025-37851
MEDIUM
Linux Kernel - Buffer Overflow in fbdev omapfb via dispc_ovl_setup
CVSS 5.5
CVE-2025-43708
LOW
VisiCut 2.1 - Denial of Service via Nested XML Set Elements
CVSS 3.3
CVE-2025-32387
MEDIUM
Helm < 3.17.3 - Stack-based Buffer Overflow via Deeply Nested JSON Schema References
CVSS 6.5
CVE-2025-1492
HIGH
Wireshark 4.2.0-4.2.10 and 4.4.0-4.4.3 - Denial of Service via Bundle Protocol and CBOR Dissector
CVSS 7.8
CVE-2024-58370
MEDIUM
SurrealDB before 1.1.0 Uncontrolled Recursion Denial of Service
CVSS 6.5
CVE-2024-58264
LOW
serde-json-wasm < 1.0.1 - Uncontrolled Recursion via Deeply Nested JSON Data
CVSS 3.2
CVE-2024-12910
MEDIUM
Llamaindex < 0.12.9 - Denial of Service
CVSS 5.9
CVE-2024-58103
MEDIUM
Square Wire <5.2.0 - Info Disclosure
CVSS 5.8
CVE-2024-8176
HIGH
Red Hat Enterprise Linux 10 - Denial of Service via Recursive Entity Expansion in libexpat
CVSS 7.5
CVE-2024-58102
MEDIUM
Datalust Seq <2024.3.13545 - Stack Consumption
CVSS 5.7
CVE-2024-57257
LOW
Das U-Boot <2025.01-rc1 - Buffer Overflow
CVSS 2.0
CVE-2024-57699
HIGH
Netplex Json-smart 2.5.0-2.5.1 - Denial of Service via Crafted JSON Input
CVSS 7.5
CVE-2024-54731
MEDIUM
CPDF < 2.8 - Denial of Service via Stack Consumption
CVSS 4.0
CVE-2024-49363
HIGH
Misskey <= 2024.10.1 - Unauthenticated Denial of Service via Proxy Loop Amplification
CVSS 7.4
Details
Vulnerabilities
474