CWE-835

Loop with Unreachable Exit Condition ('Infinite Loop')

Parent: CWE-834 - Excessive Iteration

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

887 vulnerabilities with CWE-835
CVE-2025-38727 MEDIUM
Linux Kernel - Denial of Service via Infinite Loop in netlink_unicast()
CVSS 5.5
CVE-2025-38692 MEDIUM
Linux Kernel 5.7-6.6.102, 6.7-6.12.42, 6.13-6.15.10, 6.16-6.16.1 - Denial of Service via exFAT Cluster Chain Loop
CVSS 5.5
CVE-2025-38649 MEDIUM
Linux Kernel 6.14-6.15.9, 6.16.0 - Denial of Service via Coresight Infinite Loop
CVSS 5.5
CVE-2025-38588 MEDIUM
Linux Kernel - Infinite Loop in rt6_nlmsg_size() via fib6_siblings List Traversal
CVSS 5.5
CVE-2025-38587 MEDIUM
Linux Kernel - Infinite Loop in fib6_info_uses_dev()
CVSS 5.5
CVE-2025-51986 HIGH
cwalter-at freemodbus <2018-09-12 - DoS
CVSS 7.5
CVE-2025-20253 HIGH
Cisco Adaptive Security Appliance (ASA) Software - Denial of Service via IKEv2 Packet Processing
CVSS 8.6
CVE-2025-20243 HIGH
Cisco Secure Firewall ASA/FTD - DoS
CVSS 8.6
CVE-2025-20217 HIGH
Cisco Firepower Threat Defense Software - Denial of Service via Snort 3 Packet Inspection
CVSS 8.6
CVE-2025-20136 HIGH
Cisco ASA Software Unauthenticated DoS via NAT DNS Inspection Infinite Loop
CVSS 8.6
CVE-2025-7054 MEDIUM
Cloudflare quiche 0.15.0-0.24.5 - Unauthenticated Denial of Service via RETIRE_CONNECTION_ID Frame Infinite Loop
CVSS 6.5
CVE-2025-8194 HIGH
CPython TarFile Extraction Infinite Loop Vulnerability
CVSS 7.5
CVE-2025-53015 HIGH
ImageMagick 7.1.1-7 - Denial of Service via Infinite Loop in XMP File Conversion
CVSS 7.5
CVE-2025-53628 HIGH
cpp-httplib <0.20.1 - Memory Corruption
CVSS 8.8
CVE-2025-42954 LOW
SAP NetWeaver Business Warehouse CCAW - DoS
CVSS 2.7
CVE-2025-2962 HIGH
Zephyr < 4.1.0 - Denial of Service via DNS Infinite Loop
CVSS 7.5
CVE-2025-6365 MEDIUM
HobbesOSR Kitten < 2023-05-18 - Denial of Service via set_pte_at Function
CVSS 5.7
CVE-2025-0673 HIGH
GitLab CE/EE <17.10.8-18.0.2 - Open Redirect
CVSS 7.5
CVE-2025-48879 MEDIUM
OctoPrint <= 1.11.1 - Unauthenticated Denial of Service via Malformed Multipart Form Data
CVSS 6.5
CVE-2025-30145 HIGH
GeoServer <2.27.0-2.26.3-2.25.7 - DoS
CVSS 7.5
CVE-2025-5399 HIGH
curl 8.13.0-8.14.1 - Denial of Service via WebSocket Packet Processing
CVSS 7.5
CVE-2025-38001 HIGH
Linux Kernel 5.0.1-6.15.0 Use-After-Free and Infinite Loop via HFSC and NETEM
CVSS 7.8
CVE-2025-37859 MEDIUM
Linux Kernel 5.3.18-5.3.99 - Infinite Loop in Page Pool Release Retry
CVSS 5.5
CVE-2025-3857 HIGH
Amazon.IonDotnet < 1.3.1 - Denial of Service via RawBinaryReader Binary Deserialization
CVSS 7.5
CVE-2025-32947 HIGH
PeerTube < 7.1.1 - Denial of Service via ActivityPub Inbox Endpoint
CVSS 7.5
Details
Vulnerabilities 887