← Back
CWE-674

531 CVEs • Abstraction: Class

Uncontrolled Recursion

The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

JSON object

Loading...

CVEs (531)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Foxitsoftware
2Pdf Editor
Pdf Reader
Jun 17, 2026
Aug 11, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Foxit PDF Reader before 11.0.1 and PDF Editor before 11.0.1. It allows stack consumption during recursive processing of embedded XML nodes.
2Elastic
Oracle
2Communications Cloud Native Core Automated Test Suite
Elasticsearch
Jun 17, 2026
Jul 26, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In Elasticsearch versions before 7.13.3 and 6.8.17 an uncontrolled recursion vulnerability that could lead to a denial of service attack was identified in the Elasticsearch Grok parser. A user with the ability to submit...Show more
In Elasticsearch versions before 7.13.3 and 6.8.17 an uncontrolled recursion vulnerability that could lead to a denial of service attack was identified in the Elasticsearch Grok parser. A user with the ability to submit arbitrary queries to Elasticsearch could create a malicious Grok query that will crash the Elasticsearch node.Show less
4Debian
ScirubyUblockorigin+1 more
4Debian Linux
NmatrixUblock Origin+1 more
Jun 17, 2026
Jul 18, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
uBlock Origin before 1.36.2 and nMatrix before 4.4.9 support an arbitrary depth of parameter nesting for strict blocking, which allows crafted web sites to cause a denial of service (unbounded recursion that can trigger...Show more
uBlock Origin before 1.36.2 and nMatrix before 4.4.9 support an arbitrary depth of parameter nesting for strict blocking, which allows crafted web sites to cause a denial of service (unbounded recursion that can trigger memory consumption and a loss of all blocking functionality).Show less
1Linuxfoundation
1Grpc Swift
Jun 17, 2026
Jul 9, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
HTTP2ToRawGRPCServerCodec in gRPC Swift 1.1.1 and earlier allows remote attackers to deny service via the delivery of many small messages within a single HTTP/2 frame, leading to Uncontrolled Recursion and stack consumpt...Show more
HTTP2ToRawGRPCServerCodec in gRPC Swift 1.1.1 and earlier allows remote attackers to deny service via the delivery of many small messages within a single HTTP/2 frame, leading to Uncontrolled Recursion and stack consumption.Show less
1Mikrotik
1Routeros
Jun 17, 2026
Jul 7, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Mikrotik RouterOs 6.44.5 (long-term tree) suffers from an stack exhaustion vulnerability in the /nova/bin/net process. An authenticated remote attacker can cause a Denial of Service due to overloading the systems CPU.
1Tianocore
1Edk2
Jun 17, 2026
Jun 11, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
An unlimited recursion in DxeCore in EDK II.
2Gnu
Netapp
2Binutils
Ontap Select Deploy Administration Utility
Jun 17, 2026
Jun 2, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A flaw was discovered in GNU libiberty within demangle_path() in rust-demangle.c, as distributed in GNU Binutils version 2.36. A crafted symbol can cause stack memory to be exhausted leading to a crash.
1Cesanta
1Mjs
Jun 17, 2026
May 28, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Stack overflow vulnerability in parse_equality Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file.
1Cesanta
1Mjs
Jun 17, 2026
May 28, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Stack overflow vulnerability in parse_comparison Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file.
1Cesanta
1Mjs
Jun 17, 2026
May 28, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Stack overflow vulnerability in parse_shifts Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file.
1Cesanta
1Mjs
Jun 17, 2026
May 28, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Stack overflow vulnerability in parse_plus_minus Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file.
1Cesanta
1Mjs
Jun 17, 2026
May 28, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Stack overflow vulnerability in parse_mul_div_rem Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file.
1Cesanta
1Mjs
Jun 17, 2026
May 28, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Stack overflow vulnerability in parse_unary Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file.
1Cesanta
1Mjs
Jun 17, 2026
May 28, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Stack overflow vulnerability in parse_statement_list Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file.
1Cesanta
1Mjs
Jun 17, 2026
May 28, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Stack overflow vulnerability in parse_statement Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file.
1Cesanta
1Mjs
Jun 17, 2026
May 28, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Stack overflow vulnerability in parse_block Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file.
1Cesanta
1Mjs
Jun 17, 2026
May 28, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Stack overflow vulnerability in parse_value Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file.
1Cesanta
1Mjs
Jun 17, 2026
May 28, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Stack overflow vulnerability in parse_array Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file.
2Fedoraproject
Golang
2Fedora
Go
Jun 17, 2026
May 27, 2021
N/A· v4
5.9 MEDIUM· v3
2.6 LOW· v2
net/http in Go before 1.15.12 and 1.16.x before 1.16.4 allows remote attackers to cause a denial of service (panic) via a large header to ReadRequest or ReadResponse. Server, Transport, and Client can each be affected in...Show more
net/http in Go before 1.15.12 and 1.16.x before 1.16.4 allows remote attackers to cause a denial of service (panic) via a large header to ReadRequest or ReadResponse. Server, Transport, and Client can each be affected in some configurations.Show less
3Fedoraproject
Podofo ProjectRedhat
3Enterprise Linux
FedoraPodofo
Jun 17, 2026
May 26, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A flaw was found in PoDoFo 0.9.7. An uncontrolled recursive call in PdfNamesTree::AddToDictionary function in src/podofo/doc/PdfNamesTree.cpp can lead to a stack overflow.