VYPR

CWE-674

Uncontrolled Recursion

ClassDraft

Description

The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-230 · CAPEC-231

CVEs mapped to this weakness (496)

page 22 of 25
  • CVE-2026-9358MedMay 24, 2026
    risk 0.21cvss 4.3epss 0.00

    A vulnerability was determined in postcss-selector-parser up to 6.1.2/7.1.2. Affected is the function toString of the file src/selectors/container.js of the component AST Serialization. Executing a manipulation can lead to uncontrolled recursion. It is possible to launch the…

  • CVE-2026-42445LowMay 12, 2026
    risk 0.21cvss 3.3epss 0.00

    NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an uncontrolled recursion vulnerability exists in the UFS/UFS2 filesystem image parser in NanaZip. The function GetAllPaths recurses into subdirectories without any depth limit or visited-inode…

  • CVE-2026-42355LowMay 12, 2026
    risk 0.21cvss 3.3epss 0.00

    NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an uncontrolled recursion vulnerability exists in the Electron Archive (ASAR) parser in NanaZip. When opening a crafted .asar file with deeply nested JSON in the header, both nlohmann::json::parse and…

  • CVE-2026-33532MedMar 26, 2026
    risk 0.21cvss 4.3epss 0.00

    `yaml` is a YAML parser and serialiser for JavaScript. Parsing a YAML document with a version of `yaml` on the 1.x branch prior to 1.10.3 or on the 2.x branch prior to 2.8.3 may throw a RangeError due to a stack overflow. The node resolution/composition phase uses recursive…

  • CVE-2026-4833LowMar 26, 2026
    risk 0.21cvss 3.3epss 0.00

    A weakness has been identified in Orc discount up to 3.0.1.2. This issue affects the function compile of the file markdown.c of the component Markdown Handler. This manipulation causes uncontrolled recursion. The attack is restricted to local execution. The exploit has been made…

  • CVE-2026-3388LowMar 1, 2026
    risk 0.21cvss 3.3epss 0.00

    A vulnerability was found in Squirrel up to 3.2. This affects the function SQCompiler::Factor/SQCompiler::UnaryOP of the file squirrel/sqcompiler.cpp. Performing a manipulation results in uncontrolled recursion. The attack needs to be approached locally. The exploit has been…

  • CVE-2026-3385LowMar 1, 2026
    risk 0.21cvss 3.3epss 0.00

    A vulnerability was detected in wren-lang wren up to 0.4.0. Affected is the function resolveLocal of the file src/vm/wren_compiler.c. The manipulation results in uncontrolled recursion. Attacking locally is a requirement. The exploit is now public and may be used. The project…

  • CVE-2026-3384LowMar 1, 2026
    risk 0.21cvss 3.3epss 0.00

    A security vulnerability has been detected in ChaiScript up to 6.1.0. This impacts the function chaiscript::eval::AST_Node_Impl::eval/chaiscript::eval::Function_Push_Pop of the file include/chaiscript/language/chaiscript_eval.hpp. The manipulation leads to uncontrolled…

  • CVE-2026-2641LowFeb 18, 2026
    risk 0.21cvss 3.3epss 0.00

    A weakness has been identified in universal-ctags ctags up to 6.2.1. The affected element is the function parseExpression/parseExprList of the file parsers/v.c of the component V Language Parser. Executing a manipulation can lead to uncontrolled recursion. It is possible to…

  • CVE-2025-43708LowApr 17, 2025
    risk 0.21cvss 3.3epss 0.00

    VisiCut 2.1 allows stack consumption via an XML document with nested set elements, as demonstrated by a java.util.HashMap StackOverflowError when reference='../../../set/set[2]' is used, aka an "insecure deserialization" issue.

  • CVE-2024-42369MedAug 20, 2024
    risk 0.20cvss 4.1epss 0.00

    matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. A malicious homeserver can craft a room or room structure such that the predecessors form a cycle. The matrix-js-sdk's getRoomUpgradeHistory function will infinitely recurse in this case, causing the…

  • CVE-2026-38755LowJul 15, 2026
    risk 0.19cvss 2.9epss 0.00

    A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.

  • CVE-2026-38752LowJul 15, 2026
    risk 0.19cvss 2.9epss 0.00

    A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.

  • CVE-2025-68950MedDec 30, 2025
    risk 0.19cvss 4.0epss 0.00

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12, Magick fails to check for circular references between two MVGs, leading to a stack overflow. This is a DoS vulnerability, and any situation that allows…

  • CVE-2025-67899LowDec 14, 2025
    risk 0.19cvss 2.9epss 0.00

    uriparser through 0.9.9 allows unbounded recursion and stack consumption, as demonstrated by ParseMustBeSegmentNzNc with large input containing many commas.

  • CVE-2024-54731MedJan 8, 2025
    risk 0.19cvss 4.0epss 0.00

    cpdf through 2.8 allows stack consumption via a crafted PDF document.

  • CVE-2024-4568LowMay 6, 2024
    risk 0.19cvss 2.9epss 0.00

    In Xpdf 4.05 (and earlier), a PDF object loop in the PDF resources leads to infinite recursion and a stack overflow.

  • CVE-2024-3248LowApr 2, 2024
    risk 0.19cvss 2.9epss 0.00

    In Xpdf 4.05 (and earlier), a PDF object loop in the attachments leads to infinite recursion and a stack overflow.

  • CVE-2024-3247LowApr 2, 2024
    risk 0.19cvss 2.9epss 0.00

    In Xpdf 4.05 (and earlier), a PDF object loop in an object stream leads to infinite recursion and a stack overflow.

  • CVE-2023-2664LowMay 11, 2023
    risk 0.19cvss 2.9epss 0.00

     In Xpdf 4.04 (and earlier), a PDF object loop in the embedded file tree leads to infinite recursion and a stack overflow.