← Back
CWE-674

462 CVEs • Abstraction: Class

Uncontrolled Recursion

The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

JSON object

Loading...

CVEs (462)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Re2c
1Re2c
Nov 21, 2024
Apr 29, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
re2c before 2.0 has uncontrolled recursion that causes stack consumption in find_fixed_tags.
8Apple
BroadcomCanonical+5 more
18Brocade Fabric Operating System
Cloud BackupDebian Linux+15 more
Jun 17, 2026
Apr 28, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions can result in denial of service (daemon crash).
1Flexera
1Flexnet Publisher
Jun 17, 2026
Apr 21, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A Denial of Service vulnerability related to stack exhaustion has been identified in FlexNet Publisher lmadmin.exe 11.16.2. Because the message reading function calls itself recursively given a certain condition in the r...Show more
A Denial of Service vulnerability related to stack exhaustion has been identified in FlexNet Publisher lmadmin.exe 11.16.2. Because the message reading function calls itself recursively given a certain condition in the received message, an unauthenticated remote attacker can repeatedly send messages of that type to cause a stack exhaustion condition.Show less
3Debian
OpensuseWireshark
3Debian Linux
LeapWireshark
Jun 17, 2026
Apr 10, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Wireshark 3.2.0 to 3.2.2, 3.0.0 to 3.0.9, and 2.6.0 to 2.6.15, the BACapp dissector could crash. This was addressed in epan/dissectors/packet-bacapp.c by limiting the amount of recursion.
2Debian
Videolabs
2Debian Linux
Libmicrodns
Jun 17, 2026
Mar 24, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An exploitable denial-of-service vulnerability exists in the resource record-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing compressed labels in mDNS messages, the compression pointer is followed with...Show more
An exploitable denial-of-service vulnerability exists in the resource record-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing compressed labels in mDNS messages, the compression pointer is followed without checking for recursion, leading to a denial of service. An attacker can send an mDNS message to trigger this vulnerability.Show less
1Bloq
1Univalue
Jun 17, 2026
Mar 21, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
UniValue::read() in UniValue before 1.0.5 allow attackers to cause a denial of service (the class internal data reaches an inconsistent state) via input data that triggers an error.
1Gitlab
1Gitlab
Jun 17, 2026
Mar 13, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
GitLab 8.11 through 12.8.1 allows a Denial of Service when using several features to recursively request eachother,
1Cesnet
1Libyang
Jun 17, 2026
Jan 22, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A stack consumption issue is present in libyang before v1.0-r1 due to the self-referential union type containing leafrefs. Applications that use libyang to parse untrusted input yang files may crash.
1Nasm
1Netwide Assembler
Jun 17, 2026
Jan 4, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In Netwide Assembler (NASM) 2.14.02, stack consumption occurs in expr# functions in asm/eval.c. This potentially affects the relationships among expr0, expr1, expr2, expr3, expr4, expr5, and expr6 (and stdscan in asm/std...Show more
In Netwide Assembler (NASM) 2.14.02, stack consumption occurs in expr# functions in asm/eval.c. This potentially affects the relationships among expr0, expr1, expr2, expr3, expr4, expr5, and expr6 (and stdscan in asm/stdscan.c). This is similar to CVE-2019-6290 and CVE-2019-6291.Show less
1Ezxml Project
1Ezxml
Jun 17, 2026
Dec 31, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_ent_ok() mishandles recursion, leading to stack consumption for a crafted XML file.
5Netapp
OracleSiemens+2 more
6Cloud Backup
Mysql WorkbenchOntap Select Deploy Administration Utility+3 more
Jun 17, 2026
Dec 9, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
alter.c in SQLite through 3.30.1 allows attackers to trigger infinite recursion via certain types of self-referential views in conjunction with ALTER TABLE statements.
1Facebook
1Mcrouter
Jun 17, 2026
Dec 4, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Mcrouter prior to v0.41.0, a large struct input provided to the Carbon protocol reader could result in stack exhaustion and denial of service.
110up
1Safe Svg
Jun 17, 2026
Nov 11, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A Denial Of Service vulnerability exists in the safe-svg (aka Safe SVG) plugin through 1.9.4 for WordPress, related to unlimited recursion for a '<use ... xlink:href="#identifier">' substring.
1Imagemagick
1Imagemagick
Jun 17, 2026
Nov 11, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
ImageMagick before 7.0.9-0 allows remote attackers to cause a denial of service because XML_PARSE_HUGE is not properly restricted in coders/svg.c, related to SVG and libxml2.
1Sass Lang
1Libsass
Jun 17, 2026
Nov 6, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
LibSass 3.6.1 has uncontrolled recursion in Sass::Eval::operator()(Sass::Binary_Expression*) in eval.cpp.
1Cujo
1Smart Firewall Firmware
Nov 21, 2024
Oct 31, 2019
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
An exploitable denial-of-service vulnerability exists in the mdnscap binary of the CUJO Smart Firewall running firmware 7003. When parsing labels in mDNS packets, the firewall unsafely handles label compression pointers,...Show more
An exploitable denial-of-service vulnerability exists in the mdnscap binary of the CUJO Smart Firewall running firmware 7003. When parsing labels in mDNS packets, the firewall unsafely handles label compression pointers, leading to an uncontrolled recursion that eventually exhausts the stack, crashing the mdnscap process. An unauthenticated attacker can send an mDNS message to trigger this vulnerability.Show less
3Canonical
GnuOpensuse
3Binutils
LeapUbuntu Linux
Jun 17, 2026
Oct 10, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
find_abstract_instance in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32, allows remote attackers to cause a denial of service (infinite recursion and application c...Show more
find_abstract_instance in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32, allows remote attackers to cause a denial of service (infinite recursion and application crash) via a crafted ELF file.Show less
1Tcpdump
1Tcpdump
Dec 3, 2025
Oct 3, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The SMB parser in tcpdump before 4.9.3 has stack exhaustion in smbutil.c:smb_fdata() via recursion.
1Tcpdump
1Tcpdump
Dec 3, 2025
Oct 3, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The BGP parser in tcpdump before 4.9.3 allows stack consumption in print-bgp.c:bgp_attr_print() because of unlimited recursion.
1Foxitsoftware
1Foxit Reader
Jun 17, 2026
Sep 30, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Foxit Reader 9.6.0.25114 and earlier has two unique RecursiveCall bugs involving 3 functions exhausting available stack memory because of Uncontrolled Recursion in the V8 JavaScript engine (issue 2 of 2).