VulnSea

CWE-674

CVEs classified under CWE-674, newest first.

96 CVEsRSS

CVE-2026-76098High· 7.5
4w ago

Mistune is a Python Markdown parser with renderers and plugins

Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS through deeply nested tokens. HTML rendering creates deeply nested emphasis tokens from consecutive asterisk characters, a…

Twilightmistune · mistuneEPSS 0.28%via NVD
CVE-2026-66393High· 7.5
1mo ago

NLTK versions before 3.9.4 contain an unbounded recursion vulnerability in JSONTaggedDecoder.decode_obj() that allows attackers to cause denial of service by supplying deeply nested JSON structures

NLTK versions before 3.9.4 contain an unbounded recursion vulnerability in JSONTaggedDecoder.decode_obj() that allows attackers to cause denial of service by supplying deeply nested JSON structures. Attackers can craft JSON payloads exce…

Twilightnltk · nltkEPSS 0.36%via NVD
CVE-2026-63462High· 7.5
1mo ago

Unleash is an open-source feature management platform

Unleash is an open-source feature management platform. Prior to 7.5.2, 7.6.5, and 8.0.2, the shared OpenAPI validation error path in src/lib/error/bad-data-error.ts passes a raw request value from lodash.get to JSON.stringify in genericE…

Twilightunleash-server · unleash-serverEPSS 0.48%via NVD
CVE-2026-53531Medium
1mo ago

RaTeX is a KaTeX-compatible math rendering engine written in Rust

RaTeX is a KaTeX-compatible math rendering engine written in Rust. Prior to version 0.1.11, RaTeX’s recursive-descent parser recurses one (or more) native stack frame per nesting level at `{`, `\left`, `\sqrt{`, `^{`, etc, with no maximu…

Sunlitratex-parser · ratex-parserEPSS 0.31%via NVD
CVE-2026-54623High· 7.1
1mo ago

django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django

django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.8, the move_plugin endpoint in cms/admin/placeholderadmin.py accepts an attacker-controlled plugin_parent value with…

Twilightdjango-cms · django-cmsEPSS 0.34%via NVD
CVE-2026-40345HighPoC
1mo ago

deepmerge-ts is a typescript library providing functionality to deep merging of javascript objects

deepmerge-ts is a typescript library providing functionality to deep merging of javascript objects. Prior to 8.0.0, the deepmerge, deepmergeCustom, deepmergeInto, and deepmergeIntoCustom APIs do not track visited objects or object pairs …

Midnightdeepmerge-ts · deepmerge-tsEPSS 0.47%via NVD
CVE-2026-69220High
1mo ago

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.1, src/main/java/com/rabbitmq/client/impl/ValueReader.java permits ValueReader.readTable and ValueReade…

Twilightrabbitmq · com.rabbitmq:amqp-clientEPSS 0.40%via NVD
CVE-2026-74792High· 7.5
1mo ago

Scriban before 7.0.0 (affected versions <= 6.6.0) contains a stack overflow vulnerability in nested array initializer parsing

Scriban before 7.0.0 (affected versions <= 6.6.0) contains a stack overflow vulnerability in nested array initializer parsing. Deeply nested array initializers recurse through a path (ParseArrayInitializer → ParseExpression → ParseArrayI…

TwilightEPSS 0.31%via NVD
CVE-2026-74787High· 7.5
1mo ago

Scriban before 7.0.0 contains an uncontrolled recursion vulnerability in the object.to_json builtin function that lacks depth limits and circular reference detection

Scriban before 7.0.0 contains an uncontrolled recursion vulnerability in the object.to_json builtin function that lacks depth limits and circular reference detection. Attackers can craft templates with self-referencing objects to trigger…

TwilightEPSS 0.34%via NVD
CVE-2026-73566High· 7.5
1mo ago

node-tar is a tar archive manipulation library for Node.js

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.21, node-tar's filesFilter in src/list.ts uses the recursive mapHas helper to walk an archive entry path upward with path.dirname() and no segment cap when tar.t(..…

TwilightRed Hat · Red Hat OpenShift Dev Spaces 3.30EPSS 0.38%via NVD
CVE-2026-62295High· 7.5PoC
1mo ago

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, the JSON utility parser in org.hl7.fhir.utilities.json.parser.JsonParser enforces no maximum nesting depth for arra…

Midnighthapifhir · org.hl7.fhir.coreEPSS 0.34%via NVD
CVE-2026-62296High· 7.5
1mo ago

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, XhtmlParser.java imposes no maximum element nesting depth, so a deeply nested text.div narrative triggers unbounded…

TwilightEPSS 0.34%via NVD
CVE-2026-61483High· 7.5
1mo ago

** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue

** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are rec…

Twilightapache · lucyEPSS 0.82%via NVD
CVE-2026-66274High· 7.5
1mo ago

A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35…

A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35…

Twilightapache · qpid_proton-jEPSS 0.49%via NVD
CVE-2026-46714None
1mo ago

Misskey is an open source, federated social media platform

Misskey is an open source, federated social media platform. IVersions 8.63.0 and later, but prior to 2026.5.4, contain a vulnerability that can cause the Misskey web client to slow down or crash when it applies a malformed theme. This is…

SunlitEPSS 0.26%via NVD
CVE-2026-13506High· 7.5
1mo ago

In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard

In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X seri…

Twilightbouncycastle · bc-javaEPSS 0.31%via NVD
CVE-2026-59645High· 7.5
1mo ago

In Bouncy Castle for Java before 1.85, OER parser recurses without depth limit on self-referential IEEE 1609.2 schema

In Bouncy Castle for Java before 1.85, OER parser recurses without depth limit on self-referential IEEE 1609.2 schema. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcu…

TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.31%via NVD
GHSA-3mcp-22mf-vrw3Medium· 7.5
1mo ago

Duplicate Advisory: Axios form serializer maxDepth bypass via {} metatoken

Duplicate Advisory: Axios form serializer maxDepth bypass via {} metatoken

Sunlitaxios · axiosvia GHSA
CVE-2026-67321Medium· 7.5
1mo ago

axios before 0.33.0 contains an incomplete depth-limit bypass in toFormData.js when serializing objects with top-level keys ending in '{}'

axios before 0.33.0 contains an incomplete depth-limit bypass in toFormData.js when serializing objects with top-level keys ending in '{}'. Attackers who control object keys and nested values passed to axios form or parameter serializati…

Sunlitaxios · axiosEPSS 0.36%via NVD
CVE-2026-67313High· 7.5
1mo ago

axios versions 0.28.0 and later contain uncontrolled recursion in formDataToJSON when processing FormData field names with deeply nested bracket segments

axios versions 0.28.0 and later contain uncontrolled recursion in formDataToJSON when processing FormData field names with deeply nested bracket segments. Attackers can supply FormData with field names containing thousands of nested brac…

TwilightRed Hat · Red Hat OpenShift AI 2.25EPSS 0.43%via NVD
CVE-2026-67312High· 7.5
1mo ago

axios versions from 0.28.0 before 0.33.0 and from 1.0.0 before 1.18.0 contain uncontrolled recursion in formDataToJSON (exposed as axios.formToJSON() and used internally when serializing FormData with Content-Type: application/json)

axios versions from 0.28.0 before 0.33.0 and from 1.0.0 before 1.18.0 contain uncontrolled recursion in formDataToJSON (exposed as axios.formToJSON() and used internally when serializing FormData with Content-Type: application/json). Whe…

TwilightRed Hat · Red Hat Hardened ImagesEPSS 0.43%via NVD
GHSA-r292-9mhp-454mMedium· 5.3
1mo ago

node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection

node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection

Sunlittar · tarvia GHSA
CVE-2026-55594Medium· 5.3
1mo ago

ImageMagick: Stack Overflow in MVG decoder due to missing depth check.

ImageMagick: Stack Overflow in MVG decoder due to missing depth check.

SunlitMagick · Magick.NET-Q16-AnyCPUEPSS 0.40%via GHSA
CVE-2026-64194High· 7.5
2mo ago

Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS compression pointer chains. Net::DNS::DomainName::decode follows RFC 1035 compression pointers by recursing into itself with no depth limit

Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS compression pointer chains. Net::DNS::DomainName::decode follows RFC 1035 compression pointers by recursing into itself with no depth limit. It is possible to …

TwilightEPSS 0.42%via NVD
GHSA-hcpx-6fm6-wx23Medium
2mo ago

Axios form serializer maxDepth bypass via {} metatoken

Axios form serializer maxDepth bypass via {} metatoken

Sunlitaxios · axiosvia GHSA
GHSA-42h9-826w-cgv3Medium
2mo ago

Axios: Excessive recursion in formDataToJSON can cause denial of service

Axios: Excessive recursion in formDataToJSON can cause denial of service

Sunlitaxios · axiosvia GHSA
CVE-2025-71393None
2mo ago

SurrealDB before 2.2.2 with scripting enabled fails to properly enforce recursion limits when native functions contain embedded JavaScript that issues new queries

SurrealDB before 2.2.2 with scripting enabled fails to properly enforce recursion limits when native functions contain embedded JavaScript that issues new queries. Authenticated attackers can bypass the recursion limit by chaining native…

SunlitEPSS 0.26%via NVD
CVE-2024-58370Medium· 6.5
2mo ago

SurrealDB versions before 1.1.0 fail to enforce recursion depth limits when parsing nested SurrealQL statements including IF, RELATE, and attribute access idioms

SurrealDB versions before 1.1.0 fail to enforce recursion depth limits when parsing nested SurrealQL statements including IF, RELATE, and attribute access idioms. Authorized attackers can submit queries with excessive nesting depth to ca…

SunlitEPSS 0.49%via NVD
GHSA-mxwc-wh95-pw4gMedium· 5.3
2mo ago

Trapster Community: Unauthenticated malformed DNS compression pointers crash per-packet honeypot handler

Trapster Community: Unauthenticated malformed DNS compression pointers crash per-packet honeypot handler

Sunlittrapster · trapstervia GHSA
CVE-2026-38970High· 7.5
2mo ago

pdfcpu through v0.11.1 contains an uncontrolled-recursion denial-of-service issue in pkg/pdfcpu/model/parse.go

pdfcpu through v0.11.1 contains an uncontrolled-recursion denial-of-service issue in pkg/pdfcpu/model/parse.go. The parser descends recursively through nested PDF objects, including arrays, via ParseObjectContext() and parseArray() witho…

TwilightEPSS 0.63%via NVD
CWE-674 vulnerabilities (CVEs) — page 2 · VulnSea