CWE-674: Uncontrolled Recursion — known CVE vulnerabilities
CVEs classified under CWE-674 (Uncontrolled Recursion), ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (50)
CVE-2026-43185 — CVSS 9.8 (critical): In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix signededness bug in smb_direct_prepare_negotiation()…
CVE-2023-51803 — CVSS 9.8 (critical): LinuxServer.io Heimdall before 2.5.7 does not prevent use of icons that have non-image data such as the "<?php ?>" substring.
CVE-2021-41752 — CVSS 9.8 (critical): Stack overflow vulnerability in Jerryscript before commit e1ce7dd7271288be8c0c8136eea9107df73a8ce2 on Oct 20, 2021 due to an unbounded…
CVE-2018-1000618 — CVSS 9.8 (critical): EOSIO/eos eos version after commit f1545dd0ae2b77580c2236fdb70ae7138d2c7168 contains a stack overflow vulnerability in abi_serializer that…
CVE-2025-10728: When the module renders a Svg file that contains a <pattern> element, it might end up rendering it recursively leading to stack overflow DoS
CVE-2026-32327 — CVSS 9.1 (critical): A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted…
CVE-2026-40324 — CVSS 9.1 (critical): Hot Chocolate is an open-source GraphQL server. Prior to versions 12.22.7, 13.9.16, 14.3.1, and 15.1.14, Hot Chocolate's recursive descent…
CVE-2025-39704 — CVSS 8.8 (high): In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Fix stack protector issue in send_ipi_data() Function…
CVE-2019-9545 — CVSS 8.8 (high): An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readTextRegion() located in JBIG2Stream.cc, can be…
CVE-2019-9543 — CVSS 8.8 (high): An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readGenericBitmap() located in JBIG2Stream.cc, can be…
CVE-2019-9144 — CVSS 8.8 (high): An issue was discovered in Exiv2 0.27. There is infinite recursion at BigTiffImage::printIFD in the file bigtiffimage.cpp. This can be…
CVE-2019-9143 — CVSS 8.8 (high): An issue was discovered in Exiv2 0.27. There is infinite recursion at Exiv2::Image::printTiffStructure in the file image.cpp. This can be…
CVE-2026-106447: StableLib is a stable library of useful TypeScript and JavaScript code. Prior to 2.0.4, the @stablelib/cbor decoder recursively processes…
CVE-2026-83663: Uncontrolled Recursion vulnerability in Apache Thrift go bindings. Both Go transports satisfy a read out of a buffered frame and, when that…
CVE-2026-66858: The protocol skip routine in several Apache Thrift bindings did not apply the binding's recursion limit, so a message that nests unknown…
CVE-2026-103600: Uncontrolled recursion in the ASN.1 parser (Asn1InputStream, Asn1StreamParser) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0…
CVE-2026-102509: Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits, and Uncontrolled Recursion in the Java implementation…
CVE-2026-65651: temporalio/sqlparser accepts SQL containing deeply nested unary expressions and can return a correspondingly deep abstract syntax tree…
CVE-2026-89418: google-protobuf contains an unbounded recursion when parsing unknown protobuf group fields. An attacker can send a small crafted payload of…
CVE-2026-69220: The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.1…
CVE-2026-61551 — CVSS 8.6 (high): Icinga 2 is an open source monitoring system. Prior to 2.14.9, 2.15.4, and 2.16.2, parsing deeply nested JSON can exhaust the call stack…
CVE-2025-5302 — CVSS 8.6 (high): A denial of service vulnerability exists in the JSONReader component of the run-llama/llama_index repository, specifically in version…
CVE-2024-20311 — CVSS 8.6 (high): A vulnerability in the Locator ID Separation Protocol (LISP) feature of Cisco IOS Software and Cisco IOS XE Software could allow an…
CVE-2024-25111 — CVSS 8.6 (high): Squid is a web proxy cache. Starting in version 3.5.27 and prior to version 6.8, Squid may be vulnerable to a Denial of Service attack…
CVE-2023-50269 — CVSS 8.6 (high): Squid is a caching proxy for the Web. Due to an Uncontrolled Recursion bug in versions 2.6 through 2.7.STABLE9, versions 3.1 through 5.9…
CVE-2019-10761 — CVSS 8.3 (high): This affects the package vm2 before 3.6.11. It is possible to trigger a RangeError exception from the host rather than the "sandboxed"…
CVE-2026-96289: Uncontrolled Recursion vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended…
CVE-2026-96288: Uncontrolled Recursion, Allocation of resources without limits or throttling vulnerability in Apache Thrift Erlang bindings. This issue…
CVE-2026-94650: Uncontrolled Recursion vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.25.0. Users are…
CVE-2026-54451: Elixir protobuf is a pure Elixir implementation of Google Protobuf. From 0.8.0 until 0.16.1, services that decode attacker-controlled…
CVE-2026-40345: deepmerge-ts is a typescript library providing functionality to deep merging of javascript objects. Prior to 8.0.0, the deepmerge…
CVE-2026-8936: Fixed a VM panic caused by unbounded recursion in the grpcfuse kernel module when a container created deeply nested directories on a…
CVE-2022-41966 — CVSS 8.2 (high): XStream serializes Java objects to XML and back again. Versions prior to 1.4.20 may allow a remote attacker to terminate the application…
CVE-2019-1003011 — CVSS 8.1 (high): An information exposure and denial of service vulnerability exists in Jenkins Token Macro Plugin 2.5 and earlier in src/main/java/org/jenkin…
CVE-2026-75655 — CVSS 7.8 (high): Bridge is affected by an Uncontrolled Recursion vulnerability that could result in arbitrary code execution in the context of the current…
CVE-2026-53267 — CVSS 7.8 (high): In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_ct: bail out on template ct in get eval I noticed this…
CVE-2026-53202 — CVSS 7.8 (high): In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Fix signed integer truncation in IPC receive Fix potential…
CVE-2026-23066 — CVSS 7.8 (high): In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix recvmsg() unconditional requeue If rxrpc_recvmsg() fails…
CVE-2025-38614 — CVSS 7.8 (high): In the Linux kernel, the following vulnerability has been resolved: eventpoll: Fix semi-unbounded recursion Ensure that epoll instances can…
CVE-2025-38459 — CVSS 7.8 (high): In the Linux kernel, the following vulnerability has been resolved: atm: clip: Fix infinite recursive call of clip_push(). syzbot reported…
CVE-2025-1492 — CVSS 7.8 (high): Bundle Protocol and CBOR dissector crashes in Wireshark 4.4.0 to 4.4.3 and 4.2.0 to 4.2.10 allows denial of service via packet injection or…
CVE-2023-52761 — CVSS 7.8 (high): In the Linux kernel, the following vulnerability has been resolved: riscv: VMAP_STACK overflow detection thread-safe commit 31da94c25aea…
CVE-2024-35886 — CVSS 7.8 (high): In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix infinite recursion in fib6_dump_done(). syzkaller reported…
CVE-2024-0210 — CVSS 7.8 (high): Zigbee TLV dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture file
CVE-2021-46509 — CVSS 7.8 (high): Cesanta MJS v2.20.0 was discovered to contain a stack overflow via snquote at mjs/src/mjs_json.c.
CVE-2018-9918 — CVSS 7.8 (high): libqpdf.a in QPDF through 8.0.2 mishandles certain "expected dictionary key but found non-name object" cases, allowing remote attackers to…
CVE-2026-104020 — CVSS 7.5 (high): Uncontrolled recursion in the Ion reader in Amazon Ion Python before 0.15.0 might allow a remote unauthenticated actor to crash the…
CVE-2026-102497 — CVSS 7.5 (high): The Apache XmlSchema walker (xmlschema-walker) doesn't detect cycles in type derivation, substitution groups, model groups or attribute…