CWE-835

Loop with Unreachable Exit Condition ('Infinite Loop')

Parent: CWE-834 - Excessive Iteration

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

825 vulnerabilities with CWE-835
CVE-2026-48733 MEDIUM
ImageMagick: Infinite Loop in subimage-search with crafted image
CVSS 4.7
CVE-2026-46521 MEDIUM
ImageMagick: Heap Buffer Over-Write in MIFF encoder when using LZMA compression
CVSS 5.5
CVE-2026-46522 HIGH
ImageMagick - Infinite Loop in the MIFF decoder can lead to CPU exhaustion
CVSS 7.5
CVE-2026-49495 MEDIUM
Ghidra 10.2 < 12.1 - Denial of Service via Circular Reference in Mach-O Export Trie Parser
CVSS 5.5
CVE-2026-44186 HIGH
Apache HTTP Server: Loop in `proxy_ftp_handler` in mod_proxy_ftp
CVSS 7.3
CVE-2026-44740 MEDIUM
go-billy < 5.9.0 - Symlink Resolution Resource Exhaustion
CVSS 6.5
CVE-2026-41150 MEDIUM
Mermaid Gantt Charts - Infinite Loop Denial of Service
CVSS 5.3
CVE-2026-10028 MEDIUM
glib-networking GnuTLS Backend - Certificate Chain Denial of Service
CVSS 4.3
CVE-2026-46146 MEDIUM
ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3()
CVSS 5.5
CVE-2026-49017 HIGH
Openstack Swift - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2026-47066 HIGH
Infinite loop in Alt-Svc header parser in hackney
CVSS 7.5
CVE-2026-32739 MEDIUM
libheif is Vulnerable to Infinite Loop DoS via stts Sample Duration Lookup
CVSS 6.5
CVE-2026-42920 HIGH
F5 BIG-IP DTLS - TMM Denial of Service
CVSS 7.5
CVE-2026-42781 MEDIUM
F5 BIG-IP 16.1.0-21.1.0 - Denial of Service via ePVA Ethernet Traffic
CVSS 6.5
CVE-2026-39806 HIGH
HTTP/1 chunked decoder infinite loop on requests with trailer fields in bandit
CVSS 7.5
CVE-2026-44302 HIGH
Snappier: Infinite loop in SnappyStream decompression on malformed framed input
CVSS 7.5
CVE-2026-42899 HIGH
Microsoft ASP.NET Core - Infinite Loop Denial of Service
CVSS 7.5
CVE-2026-34962 MEDIUM
barebox ext4 Directory Parsing Infinite Loop Denial of Service
CVSS 6.2
CVE-2026-8318 MEDIUM
VectifyAI PageIndex PDF Table of Contents page_index.py toc_transformer infinite loop
CVSS 5.3
CVE-2026-7263 HIGH
DoS attack via DOMNode::C14N()
CVSS 7.5
CVE-2026-42310 MEDIUM
Pillow: PDF Parsing Trailer Infinite Loop (DoS)
CVSS 5.5
CVE-2026-41511 MEDIUM
OpenMcdf <3.1.3 CFB Directory Cycle - Denial of Service
CVSS 6.2
CVE-2026-29975 HIGH
lwjson 1.8.1 - Denial of Service via Improper Input Validation in Streaming JSON Parser
CVSS 7.5
CVE-2026-33814 HIGH
Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net
CVSS 7.5
CVE-2026-43096 MEDIUM
mshv: Fix infinite fault loop on permission-denied GPA intercepts
CVSS 5.5
Details
Vulnerabilities 825