VulnSea

CWE-835

CVEs classified under CWE-835, newest first.

107 CVEsRSS

CVE-2026-82560None
2d ago

Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width. Each =over adds its indent to the margin, which wrap() subtracts from the outp…

Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width. Each =over adds its indent to the margin, which wrap() subtracts from the outp…

SunlitEPSS 0.21%via NVD
CVE-2026-61633Low· 2.0PoC
3d ago

NanoMQ is an MQTT broker

NanoMQ is an MQTT broker. Prior to 0.24.14, the NanoMQ client function nni_mqtt_msg_decode_unsubscribe() in nng/src/supplemental/mqtt/mqtt_codec.c does not handle a failed read_uint16() while counting topics in a malformed UNSUBSCRIBE pa…

Twilightnanomq · nanomqEPSS 0.25%via NVD
CVE-2026-84446High· 7.5
3d ago

libheif is a HEIF and AVIF file format decoder and encoder

libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, crafted HEIF sequence timing and edit-list data can make Track::init_sample_timing_table() compute a logical m_num_output_samples value that exceeds the uint32_…

Twilightstrukturag · libheifEPSS 0.46%via NVD
CVE-2026-93690High· 7.5PoC
3d ago

uri-js through 4.4.1 contains a denial of service vulnerability in the removeDotSegments function that loops infinitely when a path segment begins with Unicode line or paragraph separators

uri-js through 4.4.1 contains a denial of service vulnerability in the removeDotSegments function that loops infinitely when a path segment begins with Unicode line or paragraph separators. Attackers can trigger this by calling removeDot…

Midnightgarycourt · uri-jsEPSS 0.46%via NVD
CVE-2026-68537High· 7.5
4d ago

`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants

`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants. In versions prior to 0.19.0, a body-direct child whose CSS-resolved height greatly exceeds the page height was sliced into…

Twilightfulgur-rs · fulgurEPSS 0.34%via NVD
CVE-2026-68523High· 7.5
4d ago

`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants

`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants. In versions prior to 0.19.0, a body-direct child whose CSS-resolved height greatly exceeds the page height was sliced into…

Twilightfulgur-rs · fulgurEPSS 0.34%via NVD
CVE-2026-85715High· 7.5PoC
4d ago

ExifReader is a JavaScript Exif information parser

ExifReader is a JavaScript Exif information parser. Prior to 4.41.1, ExifReader parses attacker-controlled HEIC or AVIF ISO-BMFF files in getItems() within src/image-header-iso-bmff-iloc.js and trusts iloc itemCount and extentCount value…

Midnightmattiasw · ExifReaderEPSS 0.41%via NVD
CVE-2026-81872Medium· 6.3PoC
5d ago

OpenTelemetry-Go is the Go implementation of OpenTelemetry

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the go.opentelemetry.io/otel/sdk/log BatchingProcessor can enter a tight CPU loop when attacker-driven log emission fills its asynchronous export buffer…

Twilightopen-telemetry · opentelemetry-goEPSS 0.30%via NVD
CVE-2026-62949Medium· 6.5
5d ago

AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework

AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Prior to 2.24.0, _process_channel_open and _process_channel_open_confirmation in a…

Sunlitronf · asyncsshEPSS 0.39%via NVD
CVE-2026-81876High· 7.5
5d ago

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.12, SHCParser in org.hl7.fhir.r5/src/main/java/org/hl7/fhir/r5/elementmodel/SHCParser.java can enter an infinit…

Twilighthapifhir · org.hl7.fhir.coreEPSS 0.63%via NVD
CVE-2026-20154High· 8.6
5d ago

A vulnerability in the system rate-limiting process for syslog message 419002 of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, rem…

A vulnerability in the system rate-limiting process for syslog message 419002 of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, rem…

TwilightCisco · Cisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareEPSS 0.40%via NVD
CVE-2026-84997High· 7.5PoC
5d ago

react/http is an event-driven, streaming HTTP client and server implementation for ReactPHP

react/http is an event-driven, streaming HTTP client and server implementation for ReactPHP. From 0.6.0 until 1.11.1, React\Http\Io\ChunkedDecoder could enter an infinite loop while processing a malformed Transfer-Encoding: chunked body …

Midnightreactphp · httpEPSS 0.55%via NVD
CVE-2026-69210High· 7.5
6d ago

Http4s is a Scala interface for HTTP services

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, WebSocket FrameTranscoder.bodyLength rejects extended payload lengths above Integer.MAX_VALUE but permits negative 64-bit lengths. A remote client that comple…

Twilighthttp4s · http4sEPSS 0.47%via NVD
CVE-2026-91952Medium· 6.5PoC
6d ago

FreeRDP versions before 3.31.0 contain an infinite-loop denial of service in the pool_decode_rect function when decoding AVC444 metablocks with more region rectangles than preallocated worker array size

FreeRDP versions before 3.31.0 contain an infinite-loop denial of service in the pool_decode_rect function when decoding AVC444 metablocks with more region rectangles than preallocated worker array size. A malicious RDP server can send c…

TwilightFreeRDP · FreeRDPEPSS 0.35%via NVD
CVE-2026-80489Medium· 5.9
6d ago

Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to h…

Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to h…

SunlitThe GNU C Library · glibcEPSS 0.41%via NVD
CVE-2026-77117Medium· 5.9
6d ago

Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to…

Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to…

SunlitThe GNU C Library · glibcEPSS 0.41%via NVD
CVE-2026-90816Medium· 4.3PoC
1w ago

A vulnerability was found in FFmpeg 8.0.x

A vulnerability was found in FFmpeg 8.0.x. This affects the function parse_playlist of the file libavformat/hlsproto.c of the component Duration Parser. Performing a manipulation of the argument duration/target_duration results in denial…

TwilightRed Hat · FFmpegEPSS 0.35%via NVD
CVE-2026-15923Medium· 4.6
1w ago

The Zephyr SDIO subsystem function sdio_io_rw_extended_helper() in subsys/sd/sdio.c finishes transfers with a byte-I/O loop that uses size = MIN(remaining, func->cis.max_blk_size) as the per-iteration step

The Zephyr SDIO subsystem function sdio_io_rw_extended_helper() in subsys/sd/sdio.c finishes transfers with a byte-I/O loop that uses size = MIN(remaining, func->cis.max_blk_size) as the per-iteration step. The value func->cis.max_blk_si…

Sunlitzephyrproject · zephyrEPSS 0.17%via NVD
CVE-2023-37366Low· 2.8
1w ago

An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem Exynos 9810, Exynos 9610, Exynos 9820, Exynos 980, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exyn…

An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem Exynos 9810, Exynos 9610, Exynos 9820, Exynos 980, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exyn…

SunlitSamsung · Exynos 850 firmwareEPSS 0.09%via NVD
CVE-2026-89647Medium· 5.5⚖ disputed
1w ago

kernel: ceph: do not repeat ceph_trim_dentries() if no progress possible (CVE-2026-89647)

A flaw was found in the Linux kernel's Ceph file system. The `ceph_trim_dentries()` function, when invoked by `ceph_cap_reclaim_work()`, can enter an infinite loop under specific conditions where no leases need to be reclaimed. This busy l…

SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.63%via CSAF
CVE-2026-89744Medium· 5.5⚖ disputed
1w ago

kernel: device property: fix infinite loop in fwnode_for_each_child_node() (CVE-2026-89744)

A flaw was found in the Linux kernel's device property handling. When the kernel iterates over child nodes of a firmware node (fwnode) that also has a secondary fwnode, the `fwnode_get_next_child_node()` function can enter an endless loop.…

SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.14%via CSAF
CVE-2026-89578Medium· 5.5
1w ago

kernel: dm-io: clone the source bio instead of copying its biovec (CVE-2026-89578)

A flaw was found in the Linux kernel's device mapper I/O (dm-io) component. When handling DM_IO_BIO requests, incorrect sector-based accounting for misaligned direct I/O buffers could lead to an infinite loop. This issue can cause I/O oper…

SunlitRed Hat · Red Hat Enterprise Linux 10EPSS 0.20%via CSAF
CVE-2026-89567Medium· 5.5
1w ago

kernel: jbd2: bound shrinker scans by examined checkpoint buffers (CVE-2026-89567)

A flaw was found in the Linux kernel's jbd2 shrinker. This component, which manages journal buffers, does not correctly account for busy checkpoint buffers. This oversight can cause the shrinker to hold a critical system lock for an extend…

SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.20%via CSAF
CVE-2026-80957Medium· 5.5
1w ago

kernel: dm-pcache: detect a cycle in the last-kset chain during replay (CVE-2026-80957)

A flaw was found in the `dm-pcache` component of the Linux kernel. A local attacker could exploit a vulnerability in the `cache_replay()` function, which does not properly handle a forged `last-kset` chain. By crafting a malicious chain th…

SunlitRed Hat · LinuxEPSS 0.17%via CSAF
CVE-2026-78129Medium· 5.9
1w ago

strongSwan 4.6.2 through 6.0.7 has an infinite loop in PKCS#5 decryption.

strongSwan 4.6.2 through 6.0.7 has an infinite loop in PKCS#5 decryption.

Sunlitstrongswan · strongswanEPSS 0.41%via NVD
CVE-2026-78132High· 7.5
1w ago

strongSwan 5.1.3 through 6.0.7 has an infinite loop in the x509 plugin's attribute certificate parser for ietfAttrSyntax.

strongSwan 5.1.3 through 6.0.7 has an infinite loop in the x509 plugin's attribute certificate parser for ietfAttrSyntax.

Twilightstrongswan · strongswanEPSS 0.32%via NVD
CVE-2026-89045Medium· 4.0PoC
1w ago

zstd-jni versions 1.4.8-4 through 1.5.7-13 fail to validate negative length parameters in ZstdInputStreamNoFinalizer.read(), allowing attackers to trigger infinite loops

zstd-jni versions 1.4.8-4 through 1.5.7-13 fail to validate negative length parameters in ZstdInputStreamNoFinalizer.read(), allowing attackers to trigger infinite loops. Attackers can pass negative length values to cause the read method…

Twilightluben · zstd-jniEPSS 0.12%via NVD
CVE-2026-88000Medium· 6.5PoC
1w ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1, DELETE /api/v1/chats/{id}/messages/{message_id} used the chat-history deletion helper in backend/open_webui/models/chats.py t…

Twilightopenwebui · open_webuiEPSS 0.33%via NVD
CVE-2026-87013Medium· 4.3PoC
1w ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1, POST /api/v1/folders/{id}/update/parent allowed a user to place a folder under itself or one of its descendants, while the fo…

Twilightopenwebui · open_webuiEPSS 0.28%via NVD
CVE-2026-88002Medium· 6.5
1w ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.1, the message-chain reconstruction helper in backend/open_webui/utils/misc.py advanced through a chat history by map key but tra…

Sunlitopenwebui · open_webuiEPSS 0.33%via NVD
CWE-835 vulnerabilities (CVEs) · VulnSea