VYPR

CWE-835

Loop with Unreachable Exit Condition ('Infinite Loop')

BaseIncomplete

Description

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (958)

page 45 of 48
  • CVE-2026-13397HigJul 16, 2026
    risk 0.00cvss 7.5epss 0.01

    HTML::Bare versions through 0.04 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_parse function never advances the attribute-parse state cursor on certain malformed attribute forms, looping forever. Nameless attributes such as ""…

  • CVE-2026-50647HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.01

    Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.

  • CVE-2026-50324MedJul 14, 2026
    risk 0.00cvss 5.9epss 0.01

    Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.

  • CVE-2026-54119HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.01

    Loop with unreachable exit condition ('infinite loop') in Windows Active Directory allows an unauthorized attacker to deny service over a network.

  • CVE-2026-50653HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.01

    Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.

  • CVE-2026-6684MedJul 1, 2026
    risk 0.00cvss 4.6epss 0.00

    FatFs prior to R0.16 that use GPT scanning with 'FF_LBA64 = 1' contains an issue where an unbounded loop count derived from GPT header field GPTH_PtNum, enabling extremely long or effectively infinite mount-time scans. This maps to CWE-835 (Loop with Unreachable Exit Condition).…

  • CVE-2025-64438HigFeb 3, 2026
    risk 0.00cvss 7.5epss 0.01

    Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ). Prior to versions 3.4.1, 3.3.1, and 2.6.11, a remotely triggerable Out-of-Memory (OOM) denial-of-service exists in Fast -DDS when processing RTPS GAP…

  • CVE-2026-24831HigJan 27, 2026
    risk 0.00cvss 7.5epss 0.00

    Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in ixray-team ixray-1.6-stcop.This issue affects ixray-1.6-stcop: before 1.3.

  • CVE-2026-21507HigJan 6, 2026
    risk 0.00cvss 7.5epss 0.00

    iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1 and below have an infinite loop in the IccProfile.cpp function, CalcProfileID. This issue is fixed in version 2.3.1.1.

  • CVE-2025-53628HigJul 10, 2025
    risk 0.00cvss 8.8epss 0.00

    cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.20.1, cpp-httplib does not have a limit for a unique line, permitting an attacker to explore this to allocate memory arbitrarily. This vulnerability is fixed in 0.20.1. NOTE: This…

  • CVE-2025-32947HigApr 15, 2025
    risk 0.00cvss 7.5epss 0.01

    This vulnerability allows any attacker to cause the PeerTube server to stop responding to requests due to an infinite loop in the "inbox" endpoint when receiving crafted ActivityPub activities.

  • CVE-2025-29918MedApr 10, 2025
    risk 0.00cvss 6.2epss 0.00

    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. A PCRE rule can be written that leads to an infinite loop when negated PCRE is used. Packet processing thread becomes stuck in infinite loop limiting visibility…

  • CVE-2024-53980HigNov 29, 2024
    risk 0.00cvss 7.5epss 0.01

    RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) devices and other embedded devices. A malicious actor can send a IEEE 802.15.4 packet with spoofed length byte and optionally spoofed FCS, which eventually…

  • CVE-2024-42358MedAug 6, 2024
    risk 0.00cvss 6.2epss 0.00

    PDFio is a simple C library for reading and writing PDF files. There is a denial of service (DOS) vulnerability in the TTF parser. Maliciously crafted TTF files can cause the program to utilize 100% of the Memory and enter an infinite loop. This can also lead to a…

  • CVE-2024-6061LowJun 17, 2024
    risk 0.00cvss 3.3epss 0.00

    A vulnerability has been found in GPAC 2.5-DEV-rev228-g11067ea92-master and classified as problematic. Affected by this vulnerability is the function isoffin_process of the file src/filters/isoffin_read.c of the component MP4Box. The manipulation leads to infinite loop. It is…

  • CVE-2024-31949MedApr 7, 2024
    risk 0.00cvss 6.5epss 0.01

    In FRRouting (FRR) through 9.1, an infinite loop can occur when receiving a MP/GR capability as a dynamic capability because malformed data results in a pointer not advancing.

  • CVE-2024-24746HigApr 6, 2024
    risk 0.00cvss 7.5epss 0.01

    Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache NimBLE.  Specially crafted GATT operation can cause infinite loop in GATT server leading to denial of service in Bluetooth stack or device. This issue affects Apache NimBLE: through 1.6.0. Users…

  • CVE-2023-42815LowNov 13, 2023
    risk 0.00cvss 3.1epss 0.01

    Kyverno is a policy engine designed for Kubernetes. A security vulnerability was found in Kyverno where an attacker could cause denial of service of Kyverno. The vulnerability was in Kyvernos Notary verifier. An attacker would need control over the registry from which Kyverno…

  • CVE-2023-42814LowNov 13, 2023
    risk 0.00cvss 3.1epss 0.01

    Kyverno is a policy engine designed for Kubernetes. A security vulnerability was found in Kyverno where an attacker could cause denial of service of Kyverno. The vulnerable component in Kyvernos Notary verifier. An attacker would need control over the registry from which Kyverno…

  • CVE-2023-4010Jul 31, 2023
    risk 0.00cvss —epss 0.01

    Rejected reason: Rejected because the CVE description attributes a vulnerability to a non-existent Linux kernel function (usb_giveback_urb()) and the reported issue cannot be mapped to any valid codebase.