VYPR

CWE-835

Loop with Unreachable Exit Condition ('Infinite Loop')

BaseIncomplete

Description

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (909)

page 5 of 46
  • CVE-2025-41074HigNov 20, 2025
    risk 0.49cvss 7.5epss 0.00

    Vulnerability in LimeSurvey 6.13.0 in the endpoint /optout that causes infinite HTTP redirects when accessed directly. This behavior can be exploited to generate a Denegation of Service (DoS attack), by exhausting server or client resources. The system is unable to break the…

  • CVE-2025-63829HigNov 18, 2025
    risk 0.49cvss 7.5epss 0.00

    eProsima Fast-DDS v3.3 and before has an infinite loop vulnerability caused by integer overflow in the Time_t:: fraction() function.

  • CVE-2025-51986HigAug 14, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in the demo/LINUXTCP implementation of cwalter-at freemodbus v.2018-09-12 allowing attackers to reach an infinite loop via a crafted length value for a packet.

  • CVE-2025-2962HigJun 24, 2025
    risk 0.49cvss 7.5epss 0.00

    A denial-of-service issue in the dns implemenation could cause an infinite loop.

  • CVE-2025-0673HigJun 12, 2025
    risk 0.49cvss 7.5epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2, allow an attacker to trigger an infinite redirect loop, potentially leading to a denial of service condition.

  • CVE-2025-5399HigJun 7, 2025
    risk 0.49cvss 7.5epss 0.01

    Due to a mistake in libcurl's WebSocket code, a malicious server can send a particularly crafted packet which makes libcurl get trapped in an endless busy-loop. There is no other way for the application to escape or exit this loop other than killing the thread/process. This…

  • CVE-2024-22654HigMay 29, 2025
    risk 0.49cvss 7.5epss 0.00

    tcpreplay v4.4.4 was discovered to contain an infinite loop via the tcprewrite function at get.c.

  • CVE-2024-10907HigMar 20, 2025
    risk 0.49cvss 7.5epss 0.01

    In lm-sys/fastchat Release v0.2.36, the server fails to handle excessive characters appended to the end of multipart boundaries. This flaw can be exploited by sending malformed multipart requests with arbitrary characters at the end of the boundary. Each extra character is…

  • CVE-2024-10829HigMar 20, 2025
    risk 0.49cvss 7.5epss 0.01

    A Denial of Service (DoS) vulnerability in the multipart request boundary processing mechanism of eosphoros-ai/db-gpt v0.6.0 allows unauthenticated attackers to cause excessive resource consumption. The server fails to handle excessive characters appended to the end of multipart…

  • CVE-2024-10821HigMar 20, 2025
    risk 0.49cvss 7.5epss 0.01

    A Denial of Service (DoS) vulnerability in the multipart request boundary processing mechanism of the Invoke-AI server (version v5.0.1) allows unauthenticated attackers to cause excessive resource consumption. The server fails to handle excessive characters appended to the end…

  • CVE-2024-40675HigJan 28, 2025
    risk 0.49cvss 7.5epss 0.00

    In parseUriInternal of Intent.java, there is a possible infinite loop due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-11941HigDec 5, 2024
    risk 0.49cvss 7.5epss 0.00

    A vulnerability in Drupal Core allows Excessive Allocation.This issue affects Drupal Core: from 10.2.0 before 10.2.2, from 10.1.0 before 10.1.8.

  • CVE-2024-50321HigNov 12, 2024
    risk 0.49cvss 7.5epss 0.01

    An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.

  • CVE-2024-50319HigNov 12, 2024
    risk 0.49cvss 7.5epss 0.01

    An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.

  • CVE-2024-52532HigNov 11, 2024
    risk 0.49cvss 7.5epss 0.01

    GNOME libsoup before 3.6.1 has an infinite loop, and memory consumption. during the reading of certain patterns of WebSocket data from clients.

  • CVE-2024-45692HigSep 4, 2024
    risk 0.49cvss 7.5epss 0.01

    Webmin before 2.202 and Virtualmin before 7.20.2 allow a network traffic loop via spoofed UDP packets on port 10000.

  • CVE-2024-45506HigSep 4, 2024
    risk 0.49cvss 7.5epss 0.01

    HAProxy 2.9.x before 2.9.10, 3.0.x before 3.0.4, and 3.1.x through 3.1-dev6 allows a remote denial of service for HTTP/2 zero-copy forwarding (h2_send loop) under a certain set of conditions, as exploited in the wild in 2024.

  • CVE-2024-43366HigAug 15, 2024
    risk 0.49cvss 7.5epss 0.01

    zkvyper is a Vyper compiler. Starting in version 1.3.12 and prior to version 1.5.3, since LLL IR has no Turing-incompletness restrictions, it is compiled to a loop with a much more late exit condition. It leads to a loss of funds or other unwanted behavior if the loop body…

  • CVE-2024-23352HigAug 5, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS when NAS receives ODAC criteria of length 1 and type 1 in registration accept OTA.

  • CVE-2024-40060HigJul 23, 2024
    risk 0.49cvss 7.5epss 0.01

    go-chart v2.1.1 was discovered to contain an infinite loop via the drawCanvas() function.