← Back
CWE-674

531 CVEs • Abstraction: Class

Uncontrolled Recursion

The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

JSON object

Loading...

CVEs (531)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Facebook
1Mcrouter
Jun 17, 2026
Dec 4, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Mcrouter prior to v0.41.0, a large struct input provided to the Carbon protocol reader could result in stack exhaustion and denial of service.
110up
1Safe Svg
Jun 17, 2026
Nov 11, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A Denial Of Service vulnerability exists in the safe-svg (aka Safe SVG) plugin through 1.9.4 for WordPress, related to unlimited recursion for a '<use ... xlink:href="#identifier">' substring.
1Imagemagick
1Imagemagick
Jun 17, 2026
Nov 11, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
ImageMagick before 7.0.9-0 allows remote attackers to cause a denial of service because XML_PARSE_HUGE is not properly restricted in coders/svg.c, related to SVG and libxml2.
1Sass Lang
1Libsass
Jun 17, 2026
Nov 6, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
LibSass 3.6.1 has uncontrolled recursion in Sass::Eval::operator()(Sass::Binary_Expression*) in eval.cpp.
1Cujo
1Smart Firewall Firmware
Nov 21, 2024
Oct 31, 2019
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
An exploitable denial-of-service vulnerability exists in the mdnscap binary of the CUJO Smart Firewall running firmware 7003. When parsing labels in mDNS packets, the firewall unsafely handles label compression pointers,...Show more
An exploitable denial-of-service vulnerability exists in the mdnscap binary of the CUJO Smart Firewall running firmware 7003. When parsing labels in mDNS packets, the firewall unsafely handles label compression pointers, leading to an uncontrolled recursion that eventually exhausts the stack, crashing the mdnscap process. An unauthenticated attacker can send an mDNS message to trigger this vulnerability.Show less
3Canonical
GnuOpensuse
3Binutils
LeapUbuntu Linux
Jun 17, 2026
Oct 10, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
find_abstract_instance in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32, allows remote attackers to cause a denial of service (infinite recursion and application c...Show more
find_abstract_instance in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32, allows remote attackers to cause a denial of service (infinite recursion and application crash) via a crafted ELF file.Show less
1Tcpdump
1Tcpdump
Dec 3, 2025
Oct 3, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The SMB parser in tcpdump before 4.9.3 has stack exhaustion in smbutil.c:smb_fdata() via recursion.
1Tcpdump
1Tcpdump
Dec 3, 2025
Oct 3, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The BGP parser in tcpdump before 4.9.3 allows stack consumption in print-bgp.c:bgp_attr_print() because of unlimited recursion.
1Foxitsoftware
1Foxit Reader
Jun 17, 2026
Sep 30, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Foxit Reader 9.6.0.25114 and earlier has two unique RecursiveCall bugs involving 3 functions exhausting available stack memory because of Uncontrolled Recursion in the V8 JavaScript engine (issue 2 of 2).
1Foxitsoftware
1Foxit Reader
Jun 17, 2026
Sep 30, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Foxit Reader 9.6.0.25114 and earlier has two unique RecursiveCall bugs involving 3 functions exhausting available stack memory because of Uncontrolled Recursion in the V8 JavaScript engine (issue 1 of 2).
5Canonical
DebianEclipse+2 more
6Backports Sle
Debian LinuxFedora+3 more
Jun 17, 2026
Sep 19, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In Eclipse Mosquitto 1.5.0 to 1.6.5 inclusive, if a malicious MQTT client sends a SUBSCRIBE packet containing a topic that consists of approximately 65400 or more '/' characters, i.e. the topic hierarchy separator, then...Show more
In Eclipse Mosquitto 1.5.0 to 1.6.5 inclusive, if a malicious MQTT client sends a SUBSCRIBE packet containing a topic that consists of approximately 65400 or more '/' characters, i.e. the topic hierarchy separator, then a stack overflow will occur.Show less
4Canonical
DebianFedoraproject+1 more
4Debian Linux
FedoraOniguruma+1 more
Jun 17, 2026
Sep 9, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Oniguruma before 6.9.3 allows Stack Exhaustion in regcomp.c because of recursion in regparse.c.
1Glyphandcog
1Xpdfreader
Jun 17, 2026
Sep 6, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Xpdf 3.04 has a SIGSEGV in XRef::fetch in XRef.cc after many recursive calls to Catalog::countPageTree in Catalog.cc.
1Ammonia Project
1Ammonia
Jun 17, 2026
Aug 26, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in the ammonia crate before 2.1.0 for Rust. There is uncontrolled recursion during HTML DOM tree serialization.
1Trust Dns Proto Project
1Trust Dns Proto
Nov 21, 2024
Aug 26, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in the trust-dns-proto crate before 0.5.0-alpha.3 for Rust. There is infinite recursion because DNS message compression is mishandled.
1Yaml Rust Project
1Yaml Rust
Nov 21, 2024
Aug 26, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in the yaml-rust crate before 0.4.1 for Rust. There is uncontrolled recursion during deserialization.
5Canonical
DebianDjvulibre Project+2 more
5Debian Linux
DjvulibreFedora+2 more
Jun 17, 2026
Aug 18, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In DjVuLibre 3.5.27, the sorting functionality (aka GArrayTemplate<TYPE>::sort) allows attackers to cause a denial-of-service (application crash due to an Uncontrolled Recursion) by crafting a PBM image file that is mish...Show more
In DjVuLibre 3.5.27, the sorting functionality (aka GArrayTemplate<TYPE>::sort) allows attackers to cause a denial-of-service (application crash due to an Uncontrolled Recursion) by crafting a PBM image file that is mishandled in libdjvu/GContainer.h.Show less
5Canonical
DebianLinux+2 more
10Active Iq Unified Manager
Data Availability ServicesDebian Linux+7 more
Jun 17, 2026
Aug 16, 2019
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
check_input_term in sound/usb/mixer.c in the Linux kernel through 5.2.9 mishandles recursion, leading to kernel stack exhaustion.
2Djangoproject
Opensuse
2Django
Leap
Jun 17, 2026
Aug 2, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. If passed certain inputs, django.utils.encoding.uri_to_iri could lead to significant memory usage due to a recursion w...Show more
An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. If passed certain inputs, django.utils.encoding.uri_to_iri could lead to significant memory usage due to a recursion when repercent-encoding invalid UTF-8 octet sequences.Show less
1Denx
1U Boot
Jun 17, 2026
Jul 29, 2019
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
A crafted self-referential DOS partition table will cause all Das U-Boot versions through 2019.07-rc4 to infinitely recurse, causing the stack to grow infinitely and eventually either crash or overwrite other data.