VYPR

CWE-834

Excessive Iteration

ClassIncomplete

Description

The product performs an iteration or loop without sufficiently limiting the number of times that the loop is executed.

If the iteration can be influenced by an attacker, this weakness could allow attackers to consume excessive resources such as CPU or memory. In many cases, a loop does not need to be infinite in order to cause enough resource consumption to adversely affect the product or its host system; it depends on the amount of resources consumed per iteration.

Hierarchy (View 1000)

CVEs mapped to this weakness (118)

page 1 of 6
  • CVE-2017-12587HigAug 6, 2017
    risk 0.57cvss 8.8epss 0.02

    ImageMagick 7.0.6-1 has a large loop vulnerability in the ReadPWPImage function in coders\pwp.c.

  • CVE-2024-42071HigJul 29, 2024
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: ionic: use dev_consume_skb_any outside of napi If we're not in a NAPI softirq context, we need to be careful about how we call napi_consume_skb(), specifically we need to call it with budget==0 to signal to it…

  • CVE-2026-77357HigAug 25, 2026
    risk 0.50cvss —epss 0.01

    Mesop is a Python-based UI framework that allows users to build web applications. Prior to 1.3.3, applications running in debug mode expose a GET /hot-reload endpoint whose unbounded loop depends on the user-supplied counter parameter, allowing an unauthenticated attacker to…

  • CVE-2021-35515HigJul 13, 2021
    risk 0.50cvss 7.5epss 0.12

    When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of service attack against services that use Compress' sevenz package.

  • CVE-2026-16497HigSep 8, 2026
    risk 0.49cvss 7.5epss 0.00

    NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause excessive iteration. A successful exploit of this vulnerability might lead to denial of service.

  • CVE-2025-56571HigSep 30, 2025
    risk 0.49cvss 7.5epss 0.00

    Finance.js v4.1.0 contains a Denial of Service (DoS) vulnerability via the IRR function’s depth parameter. Improper handling of the recursion/iteration limit can lead to excessive CPU usage, causing application stalls or crashes.

  • CVE-2025-6714HigJul 7, 2025
    risk 0.49cvss 7.5epss 0.00

    MongoDB Server's mongos component can become unresponsive to new connections due to incorrect handling of incomplete data. This affects MongoDB when configured with load balancer support. This issue affects MongoDB Server v6.0 prior to 6.0.23, MongoDB Server v7.0 prior to 7.0.20…

  • CVE-2024-4227HigJan 15, 2025
    risk 0.49cvss 7.5epss 0.01

    In Genivia gSOAP with a specific configuration an unauthenticated remote attacker can generate a high CPU load when forcing to parse an XML having duplicate ID attributes which can lead to a DoS.

  • CVE-2023-33953HigAug 9, 2023
    risk 0.49cvss 7.5epss 0.00

    gRPC contains a vulnerability that allows hpack table accounting errors could lead to unwanted disconnects between clients and servers in exceptional cases/ Three vectors were found that allow the following DOS attacks: - Unbounded memory buffering in the HPACK parser -…

  • CVE-2023-26513HigMar 20, 2023
    risk 0.49cvss 7.5epss 0.01

    Excessive Iteration vulnerability in Apache Software Foundation Apache Sling Resource Merger.This issue affects Apache Sling Resource Merger: from 1.2.0 before 1.4.2.

  • CVE-2021-4021HigFeb 24, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability was found in Radare2 in versions prior to 5.6.2, 5.6.0, 5.5.4 and 5.5.2. Mapping a huge section filled with zeros of an ELF64 binary for MIPS architecture can lead to uncontrolled resource consumption and DoS.

  • CVE-2021-4190HigDec 30, 2021
    risk 0.49cvss 7.5epss 0.03

    Large loop in the Kafka dissector in Wireshark 3.6.0 allows denial of service via packet injection or crafted capture file

  • CVE-2021-39924HigNov 19, 2021
    risk 0.49cvss 7.5epss 0.05

    Large loop in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file

  • CVE-2021-39923HigNov 19, 2021
    risk 0.49cvss 7.5epss 0.02

    Large loop in the PNRP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file

  • CVE-2021-39204HigSep 9, 2021
    risk 0.49cvss 7.5epss 0.02

    Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, incorrectly handles resetting of HTTP/2 streams with excessive complexity. This can lead to high CPU utilization when a large number of streams are reset. This can result in a DoS…

  • CVE-2021-3128HigApr 12, 2021
    risk 0.49cvss 7.5epss 0.02

    In ASUS RT-AX3000, ZenWiFi AX (XT8), RT-AX88U, and other ASUS routers with firmware < 3.0.0.4.386.42095 or < 9.0.0.4.386.41994, when IPv6 is used, a routing loop can occur that generates excessive network traffic between an affected device and its upstream ISP's router. This…

  • CVE-2021-3125HigApr 12, 2021
    risk 0.49cvss 7.5epss 0.01

    In TP-Link TL-XDR3230 < 1.0.12, TL-XDR1850 < 1.0.9, TL-XDR1860 < 1.0.14, TL-XDR3250 < 1.0.2, TL-XDR6060 Turbo < 1.1.8, TL-XDR5430 < 1.0.11, and possibly others, when IPv6 is used, a routing loop can occur that generates excessive network traffic between an affected device and…

  • CVE-2021-23270HigApr 12, 2021
    risk 0.49cvss 7.5epss 0.01

    In Gargoyle OS 1.12.0, when IPv6 is used, a routing loop can occur that generates excessive network traffic between an affected device and its upstream ISP's router. This occurs when a link prefix route points to a point-to-point link, a destination IPv6 address belongs to the…

  • CVE-2020-35573HigDec 20, 2020
    risk 0.49cvss 7.5epss 0.03

    srs2.c in PostSRSd before 1.10 allows remote attackers to cause a denial of service (CPU consumption) via a long timestamp tag in an SRS address.

  • CVE-2020-25201HigNov 4, 2020
    risk 0.49cvss 7.5epss 0.03

    HashiCorp Consul Enterprise version 1.7.0 up to 1.8.4 includes a namespace replication bug which can be triggered to cause denial of service via infinite Raft writes. Fixed in 1.7.9 and 1.8.5.