CWE-835

Loop with Unreachable Exit Condition ('Infinite Loop')

Parent: CWE-834 - Excessive Iteration

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

825 vulnerabilities with CWE-835
CVE-2025-53015 HIGH
ImageMagick 7.1.1-7 - Denial of Service via Infinite Loop in XMP File Conversion
CVSS 7.5
CVE-2025-53628 HIGH
cpp-httplib <0.20.1 - Memory Corruption
CVSS 8.8
CVE-2025-42954 LOW
SAP NetWeaver Business Warehouse CCAW - DoS
CVSS 2.7
CVE-2025-2962 HIGH
Zephyr < 4.1.0 - Denial of Service via DNS Infinite Loop
CVSS 7.5
CVE-2025-6365 MEDIUM
HobbesOSR Kitten < 2023-05-18 - Denial of Service via set_pte_at Function
CVSS 5.7
CVE-2025-0673 HIGH
GitLab CE/EE <17.10.8-18.0.2 - Open Redirect
CVSS 7.5
CVE-2025-48879 MEDIUM
OctoPrint <= 1.11.1 - Unauthenticated Denial of Service via Malformed Multipart Form Data
CVSS 6.5
CVE-2025-30145 HIGH
GeoServer <2.27.0-2.26.3-2.25.7 - DoS
CVSS 7.5
CVE-2025-5399 HIGH
curl 8.13.0-8.14.1 - Denial of Service via WebSocket Packet Processing
CVSS 7.5
CVE-2025-38001 MEDIUM
Linux Kernel 5.0.1-6.15.0 Use-After-Free and Infinite Loop via HFSC and NETEM
CVSS 5.5
CVE-2025-37859 MEDIUM
Linux Kernel 5.3.18-5.3.99 - Infinite Loop in Page Pool Release Retry
CVSS 5.5
CVE-2025-3857 HIGH
Amazon.IonDotnet < 1.3.1 - Denial of Service via RawBinaryReader Binary Deserialization
CVSS 7.5
CVE-2025-32947 HIGH
PeerTube < 7.1.1 - Denial of Service via ActivityPub Inbox Endpoint
CVSS 7.5
CVE-2025-29918 MEDIUM
Suricata < 7.0.9 - Denial of Service via Negated PCRE Rule Infinite Loop
CVSS 6.2
CVE-2025-32029 MEDIUM
ts-asn1-der < 1.0.4 - Denial of Service via Integer Bitwise Shift
CVE-2025-21971 MEDIUM
Linux kernel - Privilege Escalation
CVSS 5.5
CVE-2025-21942 MEDIUM
Linux Kernel 6.13.2-6.13.7 - Denial of Service via BTRFS Extent Locking Infinite Loop
CVSS 5.5
CVE-2025-21871 MEDIUM
Linux Kernel - Denial of Service via OP-TEE Supplicant Wait Loop
CVSS 5.5
CVE-2025-2838 MEDIUM
Silicon Labs Gecko OS - Unauthenticated Denial of Service via DNS Response Processing Infinite Loop
CVSS 6.5
CVE-2025-29776 HIGH
Azle 0.27.0-0.29.0 - Infinite Loop via setTimer
CVE-2025-21850 MEDIUM
Linux Kernel 6.13-6.13.5 - Denial of Service via NVMe Namespace Disabling
CVSS 5.5
CVE-2025-27497 HIGH
OpenDJ < 4.9.3 - Denial of Service via Alias Loop Dereferencing
CVE-2025-1695 MEDIUM
NGINX Unit 1.29.1-1.34.1 - Denial of Service via Java Language Module Infinite Loop
CVSS 5.3
CVE-2025-21681 MEDIUM
Linux Kernel 6.1.25-6.1.126, 6.2.0-6.6.73, 6.3.0-6.12.10 - Denial of Service via Infinite Loop in skb_tx_hash
CVSS 5.5
CVE-2025-21668 MEDIUM
Linux Kernel 5.19-6.1.126, 6.2-6.6.73, 6.7-6.12.10 - Denial of Service via Infinite Loop in imx8mp_blk_ctrl_remove
CVSS 5.5
Details
Vulnerabilities 825