VulnSea

CWE-606

CVEs classified under CWE-606, newest first.

33 CVEsRSS

CVE-2026-16652High· 7.1
today

Temporal Server did not bound the work performed while searching for a Schedule's next action time

Temporal Server did not bound the work performed while searching for a Schedule's next action time. An authenticated caller with namespace write permission could create or update a Schedule that combines a fine-grained cadence with an ex…

TwilightTemporal Technologies, Inc. · go.temporal.io/servervia NVD
CVE-2026-93653Medium· 5.5
3d ago

A denial of service flaw was found in Poppler's Splash backend

A denial of service flaw was found in Poppler's Splash backend. A crafted PDF with tiling-pattern geometry approaching the int32 boundary can cause SplashOutputDev::tilingPatternFill to compute an attacker-controlled repeat count that dr…

SunlitRed Hat · popplerEPSS 0.11%via NVD
CVE-2026-89418High· 8.7PoC
4d ago

google-protobuf contains an unbounded recursion when parsing unknown protobuf group fields

google-protobuf contains an unbounded recursion when parsing unknown protobuf group fields. An attacker can send a small crafted payload of deeply nested START_GROUP wire bytes to any Node.js service that calls the generated deserializeB…

MidnightGoogle · protobuf-javascript (aka google-protobuf npm package)EPSS 0.37%via NVD
CVE-2026-81736High· 7.5
5d ago

If a BIND resolver has cached a tree of SVCB/HTTPS AliasMode records, and is then queried for the root of that tree, the resolver will spend disproportionate CPU time constructing the response. This issue affects BIND 9 versions 9.18.0 t…

If a BIND resolver has cached a tree of SVCB/HTTPS AliasMode records, and is then queried for the root of that tree, the resolver will spend disproportionate CPU time constructing the response. This issue affects BIND 9 versions 9.18.0 t…

TwilightISC · BIND 9EPSS 0.49%via NVD
CVE-2026-91952Medium· 6.5PoC
6d ago

FreeRDP versions before 3.31.0 contain an infinite-loop denial of service in the pool_decode_rect function when decoding AVC444 metablocks with more region rectangles than preallocated worker array size

FreeRDP versions before 3.31.0 contain an infinite-loop denial of service in the pool_decode_rect function when decoding AVC444 metablocks with more region rectangles than preallocated worker array size. A malicious RDP server can send c…

TwilightFreeRDP · FreeRDPEPSS 0.35%via NVD
CVE-2026-90878Medium· 4.3PoC
6d ago

A vulnerability was determined in vllm-project vLLM up to 0.27.1

A vulnerability was determined in vllm-project vLLM up to 0.27.1. This affects an unknown part of the file /v1/chat/completions of the component Jinja Template Rendering. This manipulation of the argument chat_template causes resource co…

Twilightvllm-project · vLLMEPSS 0.30%via NVD
CVE-2026-89648High· 7.0
1w ago

kernel: ceph: cap delegated inode count in ceph_parse_deleg_inos() (CVE-2026-89648)

A flaw was found in the Linux kernel's Ceph client. A malicious or compromised Ceph Metadata Server (MDS) could send a specially crafted reply with an unbounded number of delegated inode intervals. This could cause the client to enter an i…

TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.61%via CSAF
CVE-2026-89695High· 7.0⚖ disputed
1w ago

kernel: nfsd: cap decoded POSIX ACL count to bound sort cost (CVE-2026-89695)

A flaw was found in the Linux kernel's Network File System Daemon (nfsd). The `nfsd4_decode_posixacl()` function, responsible for decoding POSIX Access Control Lists (ACLs), does not properly cap the entry count received from a client. A r…

TwilightRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.49%via CSAF
CVE-2026-89566Medium· 5.5
1w ago

In the Linux kernel, the following vulnerability has been resolved: jbd2: check need_resched() when skipping busy checkpoint buffers journal_shrink_one_cp_list() skips busy checkpoint buffers when called with JBD2_SHRINK_BUSY_SKIP

In the Linux kernel, the following vulnerability has been resolved: jbd2: check need_resched() when skipping busy checkpoint buffers journal_shrink_one_cp_list() skips busy checkpoint buffers when called with JBD2_SHRINK_BUSY_SKIP. Th…

SunlitLinux · LinuxEPSS 0.20%via NVD
CVE-2026-86250High· 7.5
2w ago

h3 versions before 2.0.1-rc.18 fail to validate the chunk count parsed from user-controlled cookie values in setChunkedCookie() and deleteChunkedCookie() functions

h3 versions before 2.0.1-rc.18 fail to validate the chunk count parsed from user-controlled cookie values in setChunkedCookie() and deleteChunkedCookie() functions. Attackers can send a crafted cookie header with an extremely large chunk…

TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.28%via NVD
CVE-2026-85730High· 8.2PoC
2w ago

smol-toml is a small, fast, and correct TOML parser and serializer

smol-toml is a small, fast, and correct TOML parser and serializer. Prior to 1.7.1, parse() can enter an infinite loop when a value inside an array or inline table is followed by a comment with no trailing newline. In src/util.ts, skipUn…

Midnightsquirrelchat · smol-tomlEPSS 0.38%via NVD
CVE-2026-77465High· 7.5⚖ disputed
2w ago

toml-node is a TOML parser for Node.js and the browser

toml-node is a TOML parser for Node.js and the browser. Prior to 4.2.0, toml.parse() uses a Peggy 5.1.0 generated recursive-descent parser in lib/parser.js whose peg$parsevalue, peg$parsearray, and peg$parseinline_table_entry functions r…

TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.36%via NVD
CVE-2026-83613High· 7.5
2w ago

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and earlier, DOMHandler.startElement in lib/dom-par…

Twilightxmldom · @xmldom/xmldomEPSS 0.34%via NVD
CVE-2026-13761None
3w ago

Pega Platform versions 7.1.0 through 25.1.2 are affected by an improper validation of inputs that are used for loop conditions, potentially leading to a denial of service or other consequences because of excessive looping.

Pega Platform versions 7.1.0 through 25.1.2 are affected by an improper validation of inputs that are used for loop conditions, potentially leading to a denial of service or other consequences because of excessive looping.

SunlitEPSS 0.25%via NVD
CVE-2026-81724High· 7.5⚖ disputed
3w ago

nltk: NLTK: Denial of Service via Uncontrolled Recursion (CVE-2026-81724)

A flaw was found in NLTK. This uncontrolled recursion vulnerability in `nltk.featstruct.FeatStructReader` allows unauthenticated attackers to cause a denial of service. Attackers can achieve this by supplying deeply nested feature-structur…

TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.27%via CSAF
CVE-2026-81722High· 7.5
3w ago

nltk: nltk PorterStemmer: Denial of Service due to inefficient token processing (CVE-2026-81722)

A flaw was found in the nltk PorterStemmer component. A remote attacker could exploit this vulnerability by providing a specially crafted, untrusted token. The inefficient algorithmic complexity in the stemming process, specifically within…

TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.36%via CSAF
CVE-2026-62901High· 7.5
1mo ago

.NET Denial of Service Vulnerability

Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network.

TwilightMicrosoft · .NET 10.0EPSS 1.1%via CVEORG
CVE-2026-71439Medium
1mo ago

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 11.6.0 until 11.16.1, Mermaid Radar Diagrams allow arbitrary large values for the ticks parameter, which can cause high …

Sunlitmermaid · mermaidEPSS 0.43%via NVD
CVE-2026-20301High· 8.6
1mo ago

A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of se…

A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of se…

Twilightcisco · iosEPSS 0.33%via NVD
CVE-2026-59647High· 7.5
1mo ago

In Bouncy Castle for Java before 1.85, CRMF/CMP password-MAC honours unbounded iteration count

In Bouncy Castle for Java before 1.85, CRMF/CMP password-MAC honours unbounded iteration count. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X …

TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.27%via NVD
CVE-2026-59874High· 7.5
2mo ago

tar: Node-tar: Denial of Service via malformed tar archive header (CVE-2026-59874)

A flaw was found in node-tar, a tar archive manipulation library for Node.js. A remote attacker could exploit this vulnerability by providing a specially crafted tar archive with a negative entry size in its header. This malformed header c…

TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 0.43%via CSAF
CVE-2026-11972None
3mo ago

When using the "tarfile" module with a file opened in "streaming mode" (mode="r|") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.

When using the "tarfile" module with a file opened in "streaming mode" (mode="r|") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.

SunlitEPSS 0.45%via NVD
CVE-2026-10143High· 7.5
3mo ago

kafka-python prior to 2.3.2 DoS via SCRAM Iteration Count in scram.py

kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in SCRAM authentication handling that allows a malicious or machine-in-the-middle broker to freeze the client event loop by supplying an excessively large iteration c…

TwilightDana Powers · kafka-pythonEPSS 0.52%via CVEORG
CVE-2026-27145Medium· 6.5PoC
3mo ago

(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries

(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SA…

TwilightGo standard library · crypto/x509EPSS 0.59%via NVD
CVE-2026-44740High· 7.5
3mo ago

github.com/go-git/go-billy: Billy: Denial of Service via crafted input due to insufficient validation (CVE-2026-44740)

A flaw was found in Billy, an interface filesystem abstraction for Go. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by providing crafted or malformed input. The issue arises from insufficient validation an…

TwilightRed Hat · Red Hat Openshift Data Foundation 4.22EPSS 0.39%via CSAF
CVE-2026-5950Medium· 5.3PoC
4mo ago

An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling a remote unauthenticated attacker to cause severe resource exhaustion by sending queries that trigger specific retry …

An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling a remote unauthenticated attacker to cause severe resource exhaustion by sending queries that trigger specific retry …

Twilightisc · bindEPSS 0.66%via NVD
CVE-2026-44289High· 7.5
4mo ago

protobufjs compiles protobuf definitions into JavaScript (JS) functions

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs could recurse without a depth limit while decoding nested protobuf data. This affected both skipping unknown group fields and g…

Twilightprotobufjs_project · protobufjsEPSS 0.63%via NVD
CVE-2026-33814High· 7.5
4mo ago

When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.

When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.

Twilightgolang · goEPSS 0.78%via NVD
CVE-2026-39820High· 7.5
4mo ago

Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.

Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.

Twilightgolang · goEPSS 0.78%via NVD
CVE-2026-41606Medium· 5.3⚖ disputed
4mo ago

Uncontrolled Recursion vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

Uncontrolled Recursion vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

Sunlitapache · thriftEPSS 1.1%via NVD
CWE-606 vulnerabilities (CVEs) · VulnSea