Skip to main content

CWE archive

CWE-674 CVEs

Programmatic archive

471 CVEs tagged with CWE-6746 Critical, 202 High, 233 Medium, 30 Low, 0 Unrated.

CVE-2026-67215

Published Jul 29, 2026

cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON Patch is applied via cJSONUtils_ApplyPatches() or cJSONUti…

CVSS 8.7 · High
evidence mentions
4

CVE-2026-58178

Published Jul 29, 2026

The Apache Traffic Server ESI plugin can recurse without bound and fetch attacker-controlled URLs. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-16192

Published Jul 28, 2026

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service vulnerability when the restConnector-2.0 feature is enabled.

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-66920

Published Jul 28, 2026

Pivotick contains an uncontrolled-recursion vulnerability when processing caller-supplied graph and node data. The affected graph algorithms recursively traversed graph edges, whi…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-58227

Published Jul 27, 2026

The Erlang/OTP ssl application does not detect cycles when reconstructing an incomplete peer certificate chain during a TLS or DTLS handshake. In ssl_certificate:handle_incomplete…

CVSS 8.7 · High
evidence mentions
7
Buzz score
33.8

CVE-2026-17501

Published Jul 27, 2026

A flaw has been found in ggml-org llama.cpp e15efe0. This vulnerability affects the function transform of the file common/json-schema-to-grammar.cpp of the component JSON-Schema-t…

CVSS 6.9 · Medium
evidence mentions
7
Buzz score
27.3

CVE-2026-63144

Published Jul 21, 2026

Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via a specially crafted search request submitted by a low-privileged authenticated user. A user wit…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-64194

Published Jul 20, 2026

Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS compression pointer chains. Net::DNS::DomainName::decode follows RFC 1035 compression pointers by rec…

CVSS 7.5 · High
evidence mentions
4
Buzz score
32.6

CVE-2026-63760

Published Jul 20, 2026

SurrealDB before 3.1.0 fails to enforce the configured recursion depth limit in the value and JSON parser when processing nested braces, brackets, or parentheses. Unauthenticated…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-63759

Published Jul 20, 2026

SurrealDB before 3.1.0 fails to enforce recursion depth limits in the type/kind parser when processing nested type annotations. Authenticated attackers can send queries with deepl…

CVSS 7.1 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-63737

Published Jul 20, 2026

SurrealDB versions before 3.1.5 contain a denial of service vulnerability where authenticated users can crash the server with queries containing long chains of operators. Attacker…

CVSS 7.1 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-71393

Published Jul 18, 2026

SurrealDB before 2.2.2 with scripting enabled fails to properly enforce recursion limits when native functions contain embedded JavaScript that issues new queries. Authenticated a…

CVSS 6.0 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2024-58370

Published Jul 18, 2026

SurrealDB versions before 1.1.0 fail to enforce recursion depth limits when parsing nested SurrealQL statements including IF, RELATE, and attribute access idioms. Authorized attac…

CVSS 7.1 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-47180

Published Jul 17, 2026

Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.5, DNSIncoming._decode_labels_at_offset recurses once per DNS-name compression pointer,…

CVSS 6.5 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2026-38755

Published Jul 15, 2026

A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.

CVSS 2.9 · Low
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2026-38752

Published Jul 15, 2026

A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.

CVSS 2.9 · Low
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2026-45133

Published Jul 14, 2026

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, when the parser is exposed to attack…

CVSS 8.2 · High
evidence mentions
6
Buzz score
29.5
Vendor/product tagsBeta · best-effort

CVE-2026-40007

Published Jul 10, 2026

Uncontrolled Recursion, Uncontrolled Resource Consumption vulnerability in Apache IoTDB. When pipe_air_gap_receiver_enabled=true, the IoTDB AirGap receiver's readLength method cal…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-59927

Published Jul 8, 2026

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the Include directive in src/mistune/directives/include.py detects only direct self-includes and no…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-14803

Published Jul 6, 2026

Mojo::JSON versions before 9.47 for Perl allow memory exhaustion via unbounded recursion in the pure-Perl decoder. The pure-Perl decode path (`_decode_value` dispatching to `_dec…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
25.4

CVE-2026-38970

Published Jul 2, 2026

pdfcpu through v0.11.1 contains an uncontrolled-recursion denial-of-service issue in pkg/pdfcpu/model/parse.go. The parser descends recursively through nested PDF objects, includi…

CVSS 7.5 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-55594

Published Jul 1, 2026

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, a missing depth check in the MVG decoder w…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-56148

Published Jul 1, 2026

Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted query…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-53329

Published Jul 1, 2026

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Use krealloc_array() in dal_vector_reserve() [Why & How] dal_vector_reserve() computes the a…

CVSS 7.0 · High
evidence mentions
8
Buzz score
27.0
Vendor/product tagsBeta · best-effort

CVE-2026-49451

Published Jun 30, 2026

The OpenAPI.NET SDK contains a useful object model for OpenAPI documents in .NET along with common serializers to extract raw OpenAPI JSON and YAML documents from the model. From…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Showing 1-25 of 471 CVEsPage 1 of 19