CWE-674: CWE-674

70
Total CVEs
1
Critical
36
High
6.7
Avg CVSS

Yearly Trend

2026
10
2025
30
2024
15
2023
4
2022
4

Top Affected Vendors

1 Linux 9
2 Debian 8
3 Netapp 4
4 Imagemagick 3
5 Fedoraproject 3
6 Ibm 3
7 Squid Cache 2
8 Wireshark 2
9 Golang 2
10 Sap 1

All CWE-674 CVEs (70)

CVE-2023-51803
9.8

This vulnerability in Heimdall allows attackers to upload malicious icons containing PHP code, potentially leading to remote code execution. It affect...

Apr 1, 2024
CVE-2024-37973
8.8

CVE-2024-37973 is a Secure Boot security feature bypass vulnerability that allows attackers to circumvent Secure Boot protections on affected systems....

Jul 9, 2024
CVE-2024-20311
8.6

An unauthenticated remote attacker can send specially crafted LISP packets to vulnerable Cisco devices, causing them to reload and creating a denial o...

Mar 27, 2024
CVE-2024-25111
8.6

CVE-2024-25111 is an uncontrolled recursion vulnerability in Squid's HTTP chunked decoder that allows remote attackers to cause denial of service by s...

Mar 6, 2024
CVE-2023-50269
8.6

Squid caching proxy versions 2.6 through 6.5 contain an uncontrolled recursion vulnerability in HTTP request parsing when the follow_x_forwarded_for f...

Dec 14, 2023
CVE-2025-38459
7.8

A race condition vulnerability in the Linux kernel's ATM CLIP (Classical IP over ATM) subsystem allows infinite recursion when ioctl(ATMARP_MKIP) is c...

Jul 25, 2025
CVE-2024-35886
7.8

A stack overflow vulnerability in the Linux kernel's IPv6 routing table dump functionality allows local attackers to trigger infinite recursion during...

May 19, 2024
CVE-2024-0210
7.8

This vulnerability in Wireshark's Zigbee TLV dissector allows attackers to cause a denial of service (crash) by injecting specially crafted packets or...

Jan 3, 2024
CVE-2021-46509
7.8

CVE-2021-46509 is a stack overflow vulnerability in Cesanta MJS v2.20.0's JSON parsing functionality that allows attackers to execute arbitrary code o...

Jan 27, 2022
CVE-2025-70955
7.5

A stack overflow vulnerability in TON Virtual Machine (TVM) allows attackers to craft smart contracts with deeply nested jump logic that exhausts stac...

Feb 13, 2026
CVE-2025-70957
7.5

This CVE describes a Denial of Service vulnerability in TON Lite Server where attackers can inject malicious Continuation objects into locally execute...

Feb 13, 2026
CVE-2025-66031
7.5

An uncontrolled recursion vulnerability in node-forge versions 1.3.1 and below allows remote attackers to craft malicious ASN.1 structures that trigge...

Nov 26, 2025
CVE-2025-9624
7.5

This vulnerability in OpenSearch allows attackers to cause Denial of Service (DoS) by submitting complex query_string inputs that overwhelm the system...

Nov 25, 2025
CVE-2025-57809
7.5

CVE-2025-57809 is an infinite recursion vulnerability in XGrammar library versions before 0.1.21. This allows attackers to cause denial of service (Do...

Aug 25, 2025
CVE-2025-23325
7.5

NVIDIA Triton Inference Server contains a vulnerability where specially crafted inputs can trigger uncontrolled recursion, potentially causing denial ...

Aug 6, 2025
CVE-2025-30193
7.5

This vulnerability allows attackers to cause DNSdist to crash by exploiting TCP connection handling, leading to denial of service. DNSdist instances c...

May 20, 2025
CVE-2025-1752
7.5

This CVE describes a Denial of Service vulnerability in the run-llama/llama_index project's KnowledgeBaseWebReader class. Attackers can crash Python p...

May 10, 2025
CVE-2024-8176
7.5

A stack overflow vulnerability in libexpat allows attackers to cause denial of service or potentially memory corruption by sending XML documents with ...

Mar 14, 2025
CVE-2024-57699
7.5

This vulnerability in Netplex Json-smart 2.5.0-2.5.1 allows attackers to cause denial of service through stack exhaustion by sending specially crafted...

Feb 5, 2025
CVE-2024-43414
7.5

A denial-of-service vulnerability in Apollo Federation's query planner allows attackers to crash GraphQL services by sending specially crafted complex...

Aug 27, 2024
CVE-2024-5971
7.5

A vulnerability in Undertow's chunked response handling causes incomplete termination of TLSv1.3 responses, leading clients to wait indefinitely. This...

Jul 8, 2024
CVE-2024-32609
7.5

This vulnerability in the HDF5 library allows attackers to cause stack consumption (stack overflow) through the H5E_printf_stack function, potentially...

May 14, 2024
CVE-2024-4340
7.5

This vulnerability in sqlparse allows attackers to cause a Denial of Service (DoS) by passing heavily nested SQL statements to the sqlparse.parse() fu...

Apr 30, 2024
CVE-2024-27454
7.5

CVE-2024-27454 is a vulnerability in orjson's loads function that fails to limit recursion depth when parsing deeply nested JSON documents. This allow...

Feb 26, 2024
CVE-2022-47374
7.5

This vulnerability affects multiple Siemens industrial control systems and allows attackers to send specially crafted HTTP(S) requests to exhaust syst...

Dec 12, 2023
CVE-2023-47163
7.5

CVE-2023-47163 is a vulnerability in Remarshal that allows unlimited expansion of YAML alias nodes, making it susceptible to Billion Laughs attacks. T...

Nov 13, 2023
CVE-2023-36632
7.5

This CVE describes a recursion vulnerability in Python's legacy email.utils.parseaddr function that allows attackers to cause a RecursionError via cra...

Jun 25, 2023
CVE-2022-24675
7.5

This vulnerability is a stack overflow in Go's encoding/pem package when processing large PEM data. It allows attackers to cause denial of service or ...

Apr 20, 2022
CVE-2022-28773
7.5

CVE-2022-28773 is an uncontrolled recursion vulnerability in SAP Web Dispatcher and SAP Internet Communication Manager that can cause a denial of serv...

Apr 12, 2022
CVE-2022-24921
7.5

This vulnerability in Go's regexp.Compile function allows attackers to cause a denial of service via stack exhaustion by providing a deeply nested reg...

Mar 5, 2022
CVE-2021-42717
7.5

CVE-2021-42717 is a denial-of-service vulnerability in ModSecurity's JSON parser where excessively nested JSON objects cause excessive CPU consumption...

Dec 7, 2021
CVE-2021-39929
7.5

This vulnerability allows denial of service attacks against Wireshark through uncontrolled recursion in the Bluetooth DHT dissector. Attackers can cra...

Nov 19, 2021
CVE-2021-42697
7.5

This vulnerability allows remote attackers to cause a Denial of Service (DoS) in Akka HTTP servers by sending HTTP requests with specially crafted Use...

Nov 2, 2021
CVE-2021-36773
7.5

This vulnerability allows malicious websites to cause denial of service in uBlock Origin and uMatrix browser extensions through crafted filter rules t...

Jul 18, 2021
CVE-2021-3530
7.5

CVE-2021-3530 is a stack exhaustion vulnerability in GNU libiberty's rust-demangle.c that allows crafted symbols to cause denial of service through ap...

Jun 2, 2021
CVE-2021-27432
7.5

This vulnerability in OPC Foundation UA .NET Standard and Legacy libraries allows attackers to trigger uncontrolled recursion leading to stack overflo...

May 20, 2021
CVE-2021-28040
7.5

This vulnerability allows attackers to cause a denial of service (DoS) in OSSEC HIDS by sending specially crafted XML with excessive nested tags, trig...

Mar 5, 2021
CVE-2025-24302
6.7

This vulnerability in Intel's TinyCBOR libraries allows authenticated users to trigger uncontrolled recursion, potentially leading to privilege escala...

Aug 12, 2025
CVE-2025-36001
6.5

This vulnerability in IBM Db2 allows authenticated users to execute specially crafted SQL statements with XML that trigger uncontrolled recursion, lea...

Jan 30, 2026
CVE-2026-24401
6.5

A vulnerability in Avahi versions 0.9rc2 and below allows remote attackers to crash the avahi-daemon service via a specially crafted mDNS response con...

Jan 24, 2026
CVE-2025-33096
6.5

This vulnerability in IBM Engineering Requirements Management Doors Next allows authenticated users to cause denial of service by uploading specially ...

Oct 12, 2025
CVE-2025-61766
6.5

The Bucket MediaWiki extension prior to version 1.0.0 contains an infinite recursion vulnerability when using the '!=' comparator in queries. This cau...

Oct 6, 2025
CVE-2025-46206
6.5

This vulnerability allows remote attackers to cause denial of service in Artifex mupdf by exploiting infinite recursion in the strip_outline() functio...

Aug 4, 2025
CVE-2025-20678
6.5

This vulnerability in MediaTek's IMS service allows remote denial of service attacks when a user equipment (UE) connects to a malicious base station. ...

Jun 2, 2025
CVE-2024-28243
6.5

KaTeX users who render untrusted mathematical expressions are vulnerable to a denial-of-service attack. Malicious input using the \edef command can ca...

Mar 25, 2024
CVE-2026-25971
6.2

ImageMagick versions before 7.1.2-15 and 6.9.13-40 contain a vulnerability where the software fails to detect circular references between two MSL (Mag...

Feb 24, 2026
CVE-2025-9714
6.2

This vulnerability allows a local attacker to cause a stack overflow via crafted XPath expressions in libxml2. It affects applications using libxml2 f...

Sep 10, 2025
CVE-2026-0990
5.9

A recursion vulnerability in libxml2's xmlCatalogXMLResolveURI function allows remote attackers to cause denial of service by crashing applications th...

Jan 15, 2026
CVE-2024-47831
5.9

A vulnerability in Next.js image optimization feature allows attackers to trigger excessive CPU consumption, leading to potential Denial of Service (D...

Oct 14, 2024
CVE-2025-53864
5.8

This vulnerability allows remote attackers to cause denial of service in Connect2id Nimbus JOSE + JWT libraries by sending JWTs with deeply nested JSO...

Jul 11, 2025

About CWE-674 (CWE-674)

Our database tracks 70 CVEs classified as CWE-674, with 1 rated critical and 36 rated high severity. The average CVSS score for CWE-674 vulnerabilities is 6.7.

External reference: View CWE-674 on MITRE CWE →

Monitor CWE-674 Vulnerabilities

Get alerted when new CWE-674 CVEs affect your infrastructure.

Start Monitoring Free