Skip to main content

CWE archive

CWE-674 CVEs

Programmatic archive

504 CVEs tagged with CWE-6747 Critical, 228 High, 239 Medium, 30 Low, 0 Unrated.

CVE-2026-69220

Published Aug 18, 2026

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.1, src/main/java/com/rabbitmq/client/impl/Val…

CVSS 8.7 · High
evidence mentions
6
Buzz score
24.5

CVE-2026-74795

Published Aug 16, 2026

Scriban before 6.6.0 contains an uncontrolled recursion vulnerability in its recursive-descent parser. The parser does not enforce a default expression depth limit (the Expression…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-74794

Published Aug 16, 2026

Scriban before 6.6.0 contains an infinite recursion vulnerability in object rendering when the ObjectRecursionLimit property defaults to unlimited. Attackers can supply circular r…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-74792

Published Aug 16, 2026

Scriban before 7.0.0 (affected versions <= 6.6.0) contains a stack overflow vulnerability in nested array initializer parsing. Deeply nested array initializers recurse through a p…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-74787

Published Aug 16, 2026

Scriban before 7.0.0 contains an uncontrolled recursion vulnerability in the object.to_json builtin function that lacks depth limits and circular reference detection. Attackers ca…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-74783

Published Aug 16, 2026

Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing ExpressionDepthLimit guard that fails to stop recursive descent parsing of deeply nested expressions. Attackers can su…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-17177

Published Aug 14, 2026

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service due to uncontrolled recursion.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-72686

Published Aug 13, 2026

A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single request containing a crafted user-supplied input. A specific internal component validates the…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-72683

Published Aug 13, 2026

A flaw in Elasticsearch allows an authenticated user with the privileges required to invoke the simulate pipeline API endpoint (https://www.elastic.co/docs/api/doc/elasticsearch/o…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-72679

Published Aug 13, 2026

Elasticsearch does not apply its configurable input length restriction to a user-supplied pattern accepted by an intervals query. Compiling a deeply nested pattern drives unbounde…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-72647

Published Aug 13, 2026

Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Serialized Data with Nested Payloads (CAPEC-230). An authenticated user holding only read privi…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-72638

Published Aug 13, 2026

Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). An authenticated user holding only low-privileged index cr…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-72636

Published Aug 13, 2026

Uncontrolled Recursion (CWE-674) in the Elasticsearch wildcard matching helper can lead to a denial of service via Excessive Allocation (CAPEC-130). The matcher used to resolve wi…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-73566

Published Aug 13, 2026

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.21, node-tar's filesFilter in src/list.ts uses the recursive mapHas helper to walk an archive entry path u…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-62296

Published Aug 7, 2026

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, XhtmlParser.java imposes no maximum element nesting depth…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-62295

Published Aug 7, 2026

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, the JSON utility parser in org.hl7.fhir.utilities.json.pa…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-32327

Published Aug 6, 2026

A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem(…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-15996

Published Aug 5, 2026

A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause excessive CPU consumption and exhaust the pool of re…

CVSS 6.6 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-61483

Published Aug 5, 2026

** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-68073

Published Aug 5, 2026

A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Broker-J: through…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-67590

Published Aug 5, 2026

A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid ProtonJ2: through…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-67552

Published Aug 5, 2026

A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Proton-Dotnet thr…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-66274

Published Aug 5, 2026

A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Proton-J: through…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-15830

Published Aug 4, 2026

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potential denial-of-service when parsi…

CVSS 6.9 · Medium
evidence mentions
8
Buzz score
40.0
Vendor/product tagsBeta · best-effort

CVE-2026-46714

Published Aug 3, 2026

Misskey is an open source, federated social media platform. IVersions 8.63.0 and later, but prior to 2026.5.4, contain a vulnerability that can cause the Misskey web client to slo…

CVSS 5.1 · Medium
evidence mentions
2
Buzz score
16.0
Showing 1-25 of 504 CVEsPage 1 of 21