VulnSea

CWE-674

CVEs classified under CWE-674, newest first.

106 CVEsRSS

GHSA-r292-9mhp-454mMedium· 5.3
2mo ago

node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection

node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection

▾ Sunlittar · tarvia GHSA
CVE-2026-55594Medium· 5.3
2mo ago

ImageMagick: Stack Overflow in MVG decoder due to missing depth check.

ImageMagick: Stack Overflow in MVG decoder due to missing depth check.

▾ SunlitMagick · Magick.NET-Q16-AnyCPUEPSS 0.40%via GHSA
CVE-2026-64194High· 7.5
2mo ago

Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS compression pointer chains. Net::DNS::DomainName::decode follows RFC 1035 compression pointers by recursing into itself with no depth limit

Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS compression pointer chains. Net::DNS::DomainName::decode follows RFC 1035 compression pointers by recursing into itself with no depth limit. It is possible to …

▾ TwilightEPSS 0.68%via NVD
GHSA-hcpx-6fm6-wx23Medium
2mo ago

Axios form serializer maxDepth bypass via {} metatoken

Axios form serializer maxDepth bypass via {} metatoken

▾ Sunlitaxios · axiosvia GHSA
GHSA-42h9-826w-cgv3Medium
2mo ago

Axios: Excessive recursion in formDataToJSON can cause denial of service

Axios: Excessive recursion in formDataToJSON can cause denial of service

▾ Sunlitaxios · axiosvia GHSA
CVE-2025-71393None
2mo ago

SurrealDB before 2.2.2 with scripting enabled fails to properly enforce recursion limits when native functions contain embedded JavaScript that issues new queries

SurrealDB before 2.2.2 with scripting enabled fails to properly enforce recursion limits when native functions contain embedded JavaScript that issues new queries. Authenticated attackers can bypass the recursion limit by chaining native…

▾ SunlitEPSS 0.46%via NVD
CVE-2024-58370Medium· 6.5
2mo ago

SurrealDB versions before 1.1.0 fail to enforce recursion depth limits when parsing nested SurrealQL statements including IF, RELATE, and attribute access idioms

SurrealDB versions before 1.1.0 fail to enforce recursion depth limits when parsing nested SurrealQL statements including IF, RELATE, and attribute access idioms. Authorized attackers can submit queries with excessive nesting depth to ca…

▾ SunlitEPSS 0.49%via NVD
GHSA-mxwc-wh95-pw4gMedium· 5.3
2mo ago

Trapster Community: Unauthenticated malformed DNS compression pointers crash per-packet honeypot handler

Trapster Community: Unauthenticated malformed DNS compression pointers crash per-packet honeypot handler

▾ Sunlittrapster · trapstervia GHSA
CVE-2026-38970High· 7.5
2mo ago

pdfcpu through v0.11.1 contains an uncontrolled-recursion denial-of-service issue in pkg/pdfcpu/model/parse.go

pdfcpu through v0.11.1 contains an uncontrolled-recursion denial-of-service issue in pkg/pdfcpu/model/parse.go. The parser descends recursively through nested PDF objects, including arrays, via ParseObjectContext() and parseArray() witho…

▾ TwilightEPSS 0.63%via NVD
GHSA-q729-696q-g9pqHigh· 7.5
2mo ago

SurrealDB has Denial of Service in JSON parser due to nested objects

SurrealDB has Denial of Service in JSON parser due to nested objects

▾ Twilightsurrealdb · surrealdbvia GHSA
GHSA-q8qp-67f9-wr3fMedium· 6.5
2mo ago

SurrealDB vulnerable to Denial of Service due to nested types annotations

SurrealDB vulnerable to Denial of Service due to nested types annotations

▾ Sunlitsurrealdb · surrealdbvia GHSA
CVE-2026-57081High· 7.5
2mo ago

Net::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustion via deeply nested bencoded input. bdecode recurses once per nested list or dictionary level with no depth cap, and each recursive call receives the remaining…

Net::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustion via deeply nested bencoded input. bdecode recurses once per nested list or dictionary level with no depth cap, and each recursive call receives the remaining…

▾ TwilightEPSS 0.49%via NVD
CVE-2026-49451High· 7.5
2mo ago

Microsoft.OpenAPI: Circular schema references may terminate OpenAPI parsing

Microsoft.OpenAPI: Circular schema references may terminate OpenAPI parsing

▾ TwilightMicrosoft · Microsoft.OpenAPIEPSS 1.2%via GHSA
CVE-2026-13757Medium· 6.2
3mo ago

A flaw was found in p11-kit

A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing n…

▾ Sunlitredhat · hardened_imagesEPSS 0.19%via NVD
GHSA-6q7j-xr26-3h2cMedium
3mo ago

Scriban: ExpressionDepthLimit guard is non-enforcing — parser-recursion DoS in 6.6.0–7.2.0 (incomplete fix for GHSA-wgh7-7m3c-fx25 / GHSA-p6q4-fgr8-vx4p)

Scriban: ExpressionDepthLimit guard is non-enforcing — parser-recursion DoS in 6.6.0–7.2.0 (incomplete fix for GHSA-wgh7-7m3c-fx25 / GHSA-p6q4-fgr8-vx4p)

▾ SunlitScriban · Scribanvia GHSA
CVE-2026-53202High· 7.8
3mo ago

In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Fix signed integer truncation in IPC receive Fix potential buffer overflow where firmware-supplied data_size is cast to signed int before being used in min…

In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Fix signed integer truncation in IPC receive Fix potential buffer overflow where firmware-supplied data_size is cast to signed int before being used in min…

▾ Twilightlinux · linux_kernelEPSS 0.16%via NVD
CVE-2026-48502High
3mo ago

MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflows

MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflows

▾ TwilightMessagePack · MessagePackEPSS 0.44%via GHSA
CVE-2026-48506High· 7.5
3mo ago

MessagePack-CSharp: MessagePackReader.Skip can recurse without enforcing maximum object graph depth

MessagePack-CSharp: MessagePackReader.Skip can recurse without enforcing maximum object graph depth

▾ TwilightMessagePack · MessagePackEPSS 0.47%via GHSA
CVE-2026-48512Medium
3mo ago

MessagePack-CSharp: JSON conversion APIs can recurse without consistent depth enforcement

MessagePack-CSharp: JSON conversion APIs can recurse without consistent depth enforcement

▾ SunlitMessagePack · MessagePackEPSS 0.40%via GHSA
CVE-2026-48513Medium
3mo ago

MessagePack-CSharp: DynamicUnionResolver-generated deserializers miss depth enforcement

MessagePack-CSharp: DynamicUnionResolver-generated deserializers miss depth enforcement

▾ SunlitMessagePack · MessagePackEPSS 0.40%via GHSA
CVE-2026-48734Medium· 5.5
3mo ago

ImageMagick Vulnerable to Stack Overflow in its MVG Decoder

ImageMagick Vulnerable to Stack Overflow in its MVG Decoder

▾ SunlitMagick · Magick.NET-Q16-AnyCPUEPSS 0.15%via GHSA
CVE-2026-54297High· 7.5
3mo ago

Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters

Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters

▾ Twilightfaraday · faradayEPSS 0.76%via GHSA
GHSA-jv2j-mqmw-xvv5Medium· 6.5
3mo ago

SurrealDB: Denial of Service via deep operator chains

SurrealDB: Denial of Service via deep operator chains

▾ Sunlitsurrealdb · surrealdbvia GHSA
CVE-2026-54269Medium· 5.3
3mo ago

protobufjs : Schema-derived names can shadow runtime-significant properties

protobufjs : Schema-derived names can shadow runtime-significant properties

▾ Sunlitprotobufjs · protobufjsEPSS 0.40%via GHSA
CVE-2026-48712High· 7.5
3mo ago

protobufjs: Denial of service through unbounded Any expansion during JSON conversion

protobufjs: Denial of service through unbounded Any expansion during JSON conversion

▾ Twilightprotobufjs · protobufjsEPSS 0.46%via GHSA
CVE-2026-6811Medium· 5.9
4mo ago

Stack exhaustion vulnerability in the MongoDB PHP driver can cause application crashes when processing deeply nested BSON documents in unusual circumstances when the source of these BSON documents is not MongoDB Server.

Stack exhaustion vulnerability in the MongoDB PHP driver can cause application crashes when processing deeply nested BSON documents in unusual circumstances when the source of these BSON documents is not MongoDB Server.

▾ Sunlitmongodb · php_driverEPSS 0.37%via NVD
CVE-2026-44289High· 7.5
4mo ago

protobufjs compiles protobuf definitions into JavaScript (JS) functions

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs could recurse without a depth limit while decoding nested protobuf data. This affected both skipping unknown group fields and g…

▾ Twilightprotobufjs_project · protobufjsEPSS 0.68%via NVD
CVE-2026-1681Medium· 6.1
4mo ago

Issuing an ICMP ping via the `net ping` shell command to a device's own IPv4 address causes the network stack to recursively re-enter the input path on the same system work-queue stack

Issuing an ICMP ping via the `net ping` shell command to a device's own IPv4 address causes the network stack to recursively re-enter the input path on the same system work-queue stack. Because the destination is recognized as a local ad…

▾ Sunlitzephyrproject · zephyrEPSS 0.14%via NVD
CVE-2026-41673High· 7.5
4mo ago

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom/xmldom prior to versions 0.9.10 and 0.8.13 and xmldom version 0.6.0 and prior, seven recursive traversals in lib/dom…

▾ TwilightEPSS 0.88%via NVD
CVE-2026-41606Medium· 5.3⚖ disputed
5mo ago

Uncontrolled Recursion vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

Uncontrolled Recursion vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

▾ Sunlitapache · thriftEPSS 1.4%via NVD
CWE-674 vulnerabilities (CVEs) — page 3 · VulnSea