VulnSea

CWE-674

CVEs classified under CWE-674, newest first.

96 CVEsRSS

CVE-2026-59168Medium· 6.2
today

Dasel is a command-line tool and library for querying, modifying, and transforming data structures

Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.11.1, parsing/json/json_reader.go decodeValue, decodeObject, and decodeArray, and parsing/xml/reader.go parseElement, …

SunlitTomWright · daselvia NVD
CVE-2026-65651High· 8.7
today

temporalio/sqlparser accepts SQL containing deeply nested unary expressions and can return a correspondingly deep abstract syntax tree without enforcing an applicable nesting limit

temporalio/sqlparser accepts SQL containing deeply nested unary expressions and can return a correspondingly deep abstract syntax tree without enforcing an applicable nesting limit. The library's String and Walk operations recursively tr…

TwilightTemporal Technologies, Inc. · github.com/temporalio/sqlparservia NVD
CVE-2026-91863High· 7.5
today

A specially crafted WS-Policy document with deeply nested policy elements can bypass Neethi's nesting-depth limit and exhaust the thread stack, crashing the parser (denial of service). Users are recommended to upgrade to version 3.2.4, w…

A specially crafted WS-Policy document with deeply nested policy elements can bypass Neethi's nesting-depth limit and exhaust the thread stack, crashing the parser (denial of service). Users are recommended to upgrade to version 3.2.4, w…

TwilightApache Software Foundation · org.apache.neethi:neethivia NVD
CVE-2026-61551High· 8.6
3d ago

Icinga 2 is an open source monitoring system

Icinga 2 is an open source monitoring system. Prior to 2.14.9, 2.15.4, and 2.16.2, parsing deeply nested JSON can exhaust the call stack because nesting depth is not bounded. The affected JSON parsing paths are reachable by unauthenticat…

TwilightIcinga · icinga2EPSS 0.51%via NVD
CVE-2026-68914High· 8.7
3d ago

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-14803. Reason: This candidate is a duplicate of CVE-2026-14803. Notes: All CVE users should reference CVE-2026-14803 instead of this candidate.

Twilightmojolicious · mojoEPSS 0.26%via NVD
CVE-2026-59156Medium· 6.5
3d ago

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.20.0, 3.1.15.0, and 3.2.0.3-beta1, A crafted fits stream containing consecutive 2880-byte head…

SunlitAcademySoftwareFoundation · OpenImageIOEPSS 0.33%via NVD
CVE-2026-93687High· 7.5PoC
3d ago

braces through 3.0.3 contains a stack overflow vulnerability in the recursive AST walkers that lack depth guards

braces through 3.0.3 contains a stack overflow vulnerability in the recursive AST walkers that lack depth guards. Attackers can supply deeply nested brace patterns under the character limit to exhaust the call stack and terminate the Nod…

Midnightmicromatch · bracesEPSS 0.41%via NVD
CVE-2026-93450High· 7.5PoC
3d ago

go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability in ordered JSON parsing and serialization due to unbounded recursion with no depth limit

go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability in ordered JSON parsing and serialization due to unbounded recursion with no depth limit. Remote unauthenticated attackers can submit deeply nested JSON docu…

Midnightgo-openapi · swagEPSS 0.66%via NVD
CVE-2026-93435High· 7.5
4d ago

redis-parser through 3.0.0 contains a denial of service vulnerability in the RESP protocol parser that allows malicious Redis endpoints to crash the client process through unbounded recursion on nested arrays

redis-parser through 3.0.0 contains a denial of service vulnerability in the RESP protocol parser that allows malicious Redis endpoints to crash the client process through unbounded recursion on nested arrays. Attackers can send crafted …

TwilightNodeRedis · redis-parserEPSS 0.45%via NVD
CVE-2026-52852Medium· 6.5
4d ago

Traccar is an open source GPS tracking system

Traccar is an open source GPS tracking system. Prior to 6.14.0, an authenticated user with permission to manage groups and request reports can create a cyclic group-parent hierarchy and request a trips or stops report for a device in tha…

Sunlittraccar · traccarEPSS 0.29%via NVD
CVE-2026-89418High· 8.7PoC
4d ago

google-protobuf contains an unbounded recursion when parsing unknown protobuf group fields

google-protobuf contains an unbounded recursion when parsing unknown protobuf group fields. An attacker can send a small crafted payload of deeply nested START_GROUP wire bytes to any Node.js service that calls the generated deserializeB…

MidnightGoogle · protobuf-javascript (aka google-protobuf npm package)EPSS 0.37%via NVD
CVE-2026-54451High· 8.2
4d ago

Elixir protobuf is a pure Elixir implementation of Google Protobuf

Elixir protobuf is a pure Elixir implementation of Google Protobuf. From 0.8.0 until 0.16.1, services that decode attacker-controlled protobuf bytes with Protobuf.Decoder can be taken offline when the schema contains a self-referential o…

Twilightelixir-protobuf · protobufEPSS 0.30%via NVD
CVE-2026-19248High· 7.1
5d ago

QDomDocument XML parsing is vulnerable to a remotely-triggerable denial-of-service crash when processing untrusted input.

QDomDocument XML parsing is vulnerable to a remotely-triggerable denial-of-service crash when processing untrusted input.

Twilightqt · qtEPSS 0.41%via NVD
CVE-2026-12358High· 7.5
6d ago

IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.

IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.

TwilightIBM · Verify Identity AccessEPSS 0.39%via NVD
CVE-2026-91968Medium· 6.5PoC
6d ago

vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the task-filter endpoint that accepts deeply nested filter expressions without recursion depth limits

vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the task-filter endpoint that accepts deeply nested filter expressions without recursion depth limits. Authenticated attackers can supply thousands of nested pa…

Twilightgo-vikunja · vikunjaEPSS 0.37%via NVD
CVE-2026-53752High· 7.5
1w ago

docx4j is an open source Java library for creating, editing, and saving OpenXML packages, including DOCX, PPTX, and XLSX files

docx4j is an open source Java library for creating, editing, and saving OpenXML packages, including DOCX, PPTX, and XLSX files. Prior to 11.5.14, PropertyResolver and adjacent helpers recursively follow the WordprocessingML w:basedOn sty…

Twilightplutext · docx4jEPSS 0.44%via NVD
CVE-2026-90472Medium· 5.3PoC
1w ago

msgpack-java through 0.9.12 contains a stack overflow vulnerability in MessageUnpacker.unpackValue() that recursively deserializes arrays and maps without nesting depth limits

msgpack-java through 0.9.12 contains a stack overflow vulnerability in MessageUnpacker.unpackValue() that recursively deserializes arrays and maps without nesting depth limits. Attackers can craft payloads with deeply nested arrays to ex…

Twilightmsgpack · msgpack-javaEPSS 0.33%via NVD
CVE-2026-88763Medium· 5.9
1w ago

A flaw was found in the skupper-router component of Red Hat Service Interconnect, which is used to provide secure communication between distributed services

A flaw was found in the skupper-router component of Red Hat Service Interconnect, which is used to provide secure communication between distributed services. The issue occurs when the router processes a specially crafted network message …

SunlitRed Hat · skupper-routerEPSS 0.25%via NVD
CVE-2026-22591High· 7.5PoC
1w ago

eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group)

eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to versions 2.6.12, 2.14.6, 3.2.4, and 3.4.3, Fast DDS’s implementation of SQL‑based content filtering …

MidnighteProsima · Fast-DDSEPSS 0.26%via NVD
CVE-2026-19201Medium· 6.6
1w ago

An uncontrolled recursion vulnerability in the Windows SIPA event log parser of Google go-attestation versions up to and including 0.6.1 allows an attacker to cause a denial of service (DoS)

An uncontrolled recursion vulnerability in the Windows SIPA event log parser of Google go-attestation versions up to and including 0.6.1 allows an attacker to cause a denial of service (DoS). The (*WinEvents).readELAMAggregation function…

SunlitGoogle · go-attestationEPSS 0.28%via NVD
CVE-2026-69378High· 7.5
1w ago

Uncontrolled recursion in Microsoft Exchange Server allows an unauthorized attacker to deny service over a network.

Uncontrolled recursion in Microsoft Exchange Server allows an unauthorized attacker to deny service over a network.

TwilightMicrosoft · Microsoft Exchange Server 2016 Cumulative Update 23EPSS 1.1%via NVD
CVE-2026-73321Medium· 6.5PoC
1w ago

XenForo before 2.3.13 contains an uncontrolled recursion vulnerability in the BBCode parser that allows authenticated attackers to cause persistent denial of service by submitting a post with deeply nested BBCode tags

XenForo before 2.3.13 contains an uncontrolled recursion vulnerability in the BBCode parser that allows authenticated attackers to cause persistent denial of service by submitting a post with deeply nested BBCode tags. Attackers can craf…

Twilightxenforo · xenforoEPSS 0.40%via NVD
CVE-2026-11573High· 7.1
1w ago

Uncontrolled recursion (CWE-674) in the QDomDocument/QDomNode serialization path of the Qt XML module (QtXml, qtbase)

Uncontrolled recursion (CWE-674) in the QDomDocument/QDomNode serialization path of the Qt XML module (QtXml, qtbase). QDomElementPrivate::save() and QDomNodePrivate::save() recurse mutually, consuming one stack frame per level of elemen…

Twilightqt · qtEPSS 0.39%via NVD
CVE-2026-17440Medium· 5.5
2w ago

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to cause a denial of service due to uncontrolled recursion.

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to cause a denial of service due to uncontrolled recursion.

Sunlitibm · app_connect_enterpriseEPSS 0.10%via NVD
CVE-2026-77465High· 7.5⚖ disputed
2w ago

toml-node is a TOML parser for Node.js and the browser

toml-node is a TOML parser for Node.js and the browser. Prior to 4.2.0, toml.parse() uses a Peggy 5.1.0 generated recursive-descent parser in lib/parser.js whose peg$parsevalue, peg$parsearray, and peg$parseinline_table_entry functions r…

TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.36%via NVD
CVE-2026-12876Medium
2w ago

NLTK: Uncontrolled resource consumption in RecursiveDescentParser via ambiguous or left-recursive grammars

NLTK: Uncontrolled resource consumption in RecursiveDescentParser via ambiguous or left-recursive grammars

Sunlitnltk · nltkvia OSV
CVE-2026-78228None
3w ago

Uncontrolled Recursion vulnerability in ash-project ash_oban allows a user who can drive a trigger's on_error action to fail on the final attempt to exhaust worker CPU and memory, denying service. The generated worker's atomic handle_er…

Uncontrolled Recursion vulnerability in ash-project ash_oban allows a user who can drive a trigger's on_error action to fail on the final attempt to exhaust worker CPU and memory, denying service. The generated worker's atomic handle_er…

SunlitEPSS 0.13%via NVD
CVE-2026-47851High· 7.5
3w ago

Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError in the ingestion thread. Spring AI 2.0.0 Spring AI 1.1.0 - 1.1.8 Spring AI 1.0.0 - 1.0.9

Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError in the ingestion thread. Spring AI 2.0.0 Spring AI 1.1.0 - 1.1.8 Spring AI 1.0.0 - 1.0.9

Twilightvmware · spring_aiEPSS 0.26%via NVD
CVE-2026-81724High· 7.5⚖ disputed
3w ago

nltk: NLTK: Denial of Service via Uncontrolled Recursion (CVE-2026-81724)

A flaw was found in NLTK. This uncontrolled recursion vulnerability in `nltk.featstruct.FeatStructReader` allows unauthenticated attackers to cause a denial of service. Attackers can achieve this by supplying deeply nested feature-structur…

TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.27%via CSAF
CVE-2026-55588Medium· 6.5⚖ disputed
3w ago

ORAS (OCI Registry As Storage) is a CLI and library for managing artifacts in OCI registries

ORAS (OCI Registry As Storage) is a CLI and library for managing artifacts in OCI registries. In ORAS CLI versions up to and including 1.3.2, the recursive referrer traversal does not track visited descriptors, so a malicious OCI registr…

Sunlitoras · oras.land/orasEPSS 0.30%via NVD
CWE-674 vulnerabilities (CVEs) · VulnSea