VulnSea

CWE-674

CVEs classified under CWE-674, newest first.

106 CVEsRSS

CVE-2026-42039High· 7.5PoC
5mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, toFormData recursively walks nested objects with no depth limit, so a deeply nested value passed as request data crashes the Node.js process wi…

▾ Midnightaxios · axiosEPSS 0.97%via NVD
CVE-2026-6862Medium· 5.5
5mo ago

A flaw was found in libefiboot, a component of efivar

A flaw was found in libefiboot, a component of efivar. The device path node parser in libefiboot fails to validate that each node's Length field is at least 4 bytes, which is the minimum size for an EFI (Extensible Firmware Interface) de…

▾ Sunlitubuntu · libefibootEPSS 0.17%via NVD
CVE-2026-30922High· 7.5PoC
6mo ago

pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion (CVE-2026-30922)

An unbounded recursion flaw has been discovered in the pypi pyasn1 library. This uncontrolled recursion occurs when decoding ASN.1 data with deeply nested structures. An attacker can supply a crafted payload containing nested SEQUENCE (0x3…

▾ MidnightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.93%via CSAF
CVE-2026-4224High· 7.5
6mo ago

When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow occurs.

When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow occurs.

▾ Twilightpython · pythonEPSS 1.2%via NVD
CVE-2026-32141High· 7.5
6mo ago

flatted is a circular JSON parser

flatted is a circular JSON parser. Prior to 3.4.0, flatted's parse() function uses a recursive revive() phase to resolve circular references in deserialized JSON. When given a crafted payload with deeply nested or self-referential $ indi…

▾ Twilightwebreflection · flattedEPSS 0.99%via NVD
CVE-2026-0994High· 7.5PoC
8mo ago

A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth ac…

A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth ac…

▾ Midnightgoogle · protobufEPSS 0.72%via NVD
CVE-2026-0990Medium· 5.9
8mo ago

A flaw was found in libxml2, an XML parsing library

A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A remote attacker cou…

▾ SunlitEPSS 0.97%via NVD
CVE-2026-0989Low· 3.7
8mo ago

A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled

A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested <include> directives. Specially crafted or overly …

▾ SunlitEPSS 0.54%via NVD
CVE-2025-10728None
11mo ago

When the module renders a Svg file that contains a <pattern> element, it might end up rendering it recursively leading to stack overflow DoS

When the module renders a Svg file that contains a <pattern> element, it might end up rendering it recursively leading to stack overflow DoS

▾ SunlitEPSS 0.22%via NVD
CVE-2022-50407Medium· 5.5
1y ago

In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/qm - increase the memory of local variables Increase the buffer to prevent stack overflow by fuzz test

In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/qm - increase the memory of local variables Increase the buffer to prevent stack overflow by fuzz test. The maximum length of the qos configuration b…

▾ Sunlitlinux · linux_kernelEPSS 0.17%via NVD
CVE-2025-57809High· 7.5
1y ago

xgrammar: XGrammar affected by Denial of Service by infinite recursion grammars (CVE-2025-57809)

A flaw was found in xgrammar. Recursive grammar definitions could trigger infinite recursion during parsing in GrammarMatcherBase::ExpandEquivalentStackElements, leading to unbounded stack growth and a segmentation fault. This vulnerabilit…

▾ TwilightRed Hat · Red Hat Enterprise Linux AI 1.5EPSS 0.47%via CSAF
CVE-2025-8732Low· 3.3
1y ago

A vulnerability was found in libxml2 up to 2.14.5

A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the function xmlParseSGMLCatalog of the component xmlcatalog. The manipulation leads to uncontrolled recursion. Attacking …

▾ SunlitEPSS 0.21%via NVD
CVE-2024-8176High· 7.5PoC
1y ago

A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents

A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents. When parsing an XML document with deeply nested entity references, libexpat can be forced to recurse ind…

▾ MidnightRed Hat · libexpatEPSS 1.3%via NVD
CVE-2024-5971High· 7.5
2y ago

A vulnerability was found in Undertow, where the chunked response hangs after the body was flushed

A vulnerability was found in Undertow, where the chunked response hangs after the body was flushed. The response headers and body were sent but the client would continue waiting as Undertow does not send the expected 0\r\n termination of…

▾ TwilightEPSS 2.9%via NVD
CVE-2022-37315High· 7.5
4y ago

graphql-go (aka GraphQL for Go) through 0.8.0 has infinite recursion in the type definition parser.

graphql-go (aka GraphQL for Go) through 0.8.0 has infinite recursion in the type definition parser.

▾ Twilightgraphql-go_project · graphql-goEPSS 1.0%via NVD
CVE-2021-45105Medium· 5.90dayPoC
4y ago

Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups

Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial …

▾ Midnightapache · log4jEPSS 100%via NVD
CWE-674 vulnerabilities (CVEs) — page 4 · VulnSea