CVE-2022-23437Medium· 6.5▾ SunlitThere's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resourc…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 2.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 25.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
12%
There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.
xerces-j <= 2.12.1agile_engineering_data_management = 6.2.1.0agile_product_lifecycle_management = 9.3.6banking_deposits_and_lines_of_credit_servicing = 2.7banking_party_management = 2.7.0communications_asap = 7.3communications_element_manager < 9.0communications_session_report_manager < 9.0communications_session_route_manager < 9.0financial_services_analytical_applications_infrastructure >= 8.0.6.0.0, <= 8.0.9.0financial_services_analytical_applications_infrastructure >= 8.1.0.0, < 8.1.2.0financial_services_behavior_detection_platform >= 8.0.6.0.0, <= 8.0.8.0financial_services_behavior_detection_platform = 8.1.1.0financial_services_behavior_detection_platform = 8.1.1.1financial_services_behavior_detection_platform = 8.1.2.0financial_services_crime_and_compliance_management_studio = 8.0.8.2.0financial_services_crime_and_compliance_management_studio = 8.0.8.3.0financial_services_enterprise_case_management = 8.0.7.1financial_services_enterprise_case_management = 8.0.7.2.0financial_services_enterprise_case_management = 8.0.8.0financial_services_enterprise_case_management = 8.0.8.1financial_services_enterprise_case_management = 8.1.1.0financial_services_enterprise_case_management = 8.1.1.1flexcube_universal_banking = 12.4.0global_lifecycle_management_nextgen_oui_framework < 13.9.4.2.2global_lifecycle_management_nextgen_oui_framework = 13.9.4.2.2global_lifecycle_management_opatch < 12.2.0.1.30health_sciences_information_manager >= 3.0.1, <= 3.0.5health_sciences_information_manager = 3.0.0.1ilearning = 6.2ilearning = 6.3peoplesoft_enterprise_peopletools = 8.58peoplesoft_enterprise_peopletools = 8.59primavera_gateway >= 17.7, <= 17.12.11primavera_gateway >= 18.8.0, <= 18.8.14primavera_gateway >= 19.12.0, <= 19.12.13primavera_gateway >= 20.12.0, <= 20.12.8product_lifecycle_analytics = 3.6.1retail_bulk_data_integration = 16.0.3.0retail_extract_transform_and_load = 13.2.8retail_financial_integration = 14.1.3.2retail_financial_integration = 15.0.3.1retail_financial_integration = 16.0.3retail_financial_integration = 19.0.1retail_integration_bus = 14.1.3.2retail_integration_bus = 15.0.3.1retail_integration_bus = 16.0.3retail_integration_bus = 19.0.1retail_merchandising_system = 16.0.3retail_merchandising_system = 19.0.1retail_service_backbone = 14.1.3.2retail_service_backbone = 15.0.3.1retail_service_backbone = 16.0.3retail_service_backbone = 19.0.1weblogic_server = 12.2.1.3.0weblogic_server = 12.2.1.4.0weblogic_server = 14.1.1.0.0active_iq_unified_managerUpgrade past the affected range:
communications_element_manager 9.0communications_session_report_manager 9.0communications_session_route_manager 9.0financial_services_analytical_applications_infrastructure 8.1.2.0global_lifecycle_management_nextgen_oui_framework 13.9.4.2.2global_lifecycle_management_opatch 12.2.0.1.30Connected by shared product, vendor, weakness, or advisory.
CVE-2020-13935High· 7.5The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104
CVE-2026-4111High· 7.5A flaw was identified in the RAR5 archive decompression logic of the libarchive library, specifically within the archive_read_data() processing path
CVE-2022-49317Medium· 5.5In the Linux kernel, the following vulnerability has been resolved: f2fs: avoid infinite loop to flush node pages xfstests/generic/475 can give EIO all the time which give an infinite loop to flush node page like below
CVE-2025-21850Critical· 9.8In the Linux kernel, the following vulnerability has been resolved: nvmet: Fix crash when a namespace is disabled The namespace percpu counter protects pending I/O, and we can only safely diable the namespace once the counter drop to z…
CVE-2025-71319High· 7.5image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-…
CVE-2026-10642Medium· 6.5The Zephyr PL011 UART driver (drivers/serial/uart_pl011.c) contains an unbounded software loop in pl011_irq_tx_enable() that repeatedly invokes the interrupt-driven application callback while the TX interrupt mask bit (PL011_IMSC_TXIM) i…