CWE-835: Infinite Loop
The product contains an iteration or loop with an exit condition that cannot be reached, leading to an infinite loop.
Yearly Trend
Top Affected Vendors
All Infinite Loop CVEs (137)
This vulnerability in MediaWiki's ApiPageSet.php allows attackers to trigger an infinite loop when querying pages with specific redirect and title con...
Oct 9, 2023This vulnerability allows an attacker to cause a denial of service by triggering an infinite loop in the scanning engine of affected WithSecure securi...
Sep 18, 2023CVE-2023-1108 is a denial-of-service vulnerability in Undertow's SSL/TLS implementation where an infinite loop in the handshake process can crash the ...
Sep 14, 2023This vulnerability in ClamAV's HFS+ filesystem parser allows remote attackers to cause denial of service by submitting crafted HFS+ images. The scanni...
Aug 16, 2023CVE-2020-35139 is a denial-of-service vulnerability in Faucet SDN Ryu's parser.py where specially crafted OFPBundleCtrlMsg messages can trigger an inf...
Aug 11, 2023This CVE describes an infinite loop vulnerability in Samba's mdssvc RPC service for Spotlight. Attackers can send specially crafted RPC packets with a...
Jul 20, 2023This vulnerability in Qt's XML parsing allows attackers to cause denial of service through infinite loops during recursive entity expansion. It affect...
Jul 13, 2023CVE-2022-37013 is a denial-of-service vulnerability in Unified Automation OPC UA C++ Demo Server where remote attackers can send a specially crafted c...
Mar 29, 2023This vulnerability in mod_gnutls (TLS module for Apache HTTPD) causes an endless loop when TLS connections timeout during blocking read operations, co...
Feb 23, 2023CVE-2022-25851 is a denial-of-service vulnerability in jpeg-js library where specially crafted JPEG images cause infinite processing loops, consuming ...
Jun 10, 2022CVE-2022-29190 is a denial-of-service vulnerability in Pion DTLS, a Go implementation of Datagram Transport Layer Security. Attackers can send special...
May 21, 2022CVE-2022-21159 is a denial-of-service vulnerability in libiec61850's parseNormalModeParameters function where specially crafted IEC 61850 network mess...
Apr 15, 2022CVE-2022-24763 is a denial-of-service vulnerability in PJSIP's XML parsing functionality that can cause applications to crash or become unresponsive. ...
Mar 30, 2022This vulnerability in BigAnt Server v5.6.06 allows attackers to cause a Denial of Service (DoS) by exploiting an infinite loop condition (CWE-835). Th...
Mar 21, 2022CVE-2022-0778 is a denial-of-service vulnerability in OpenSSL's BN_mod_sqrt() function that can cause infinite loops when parsing specially crafted ce...
Mar 15, 2022CVE-2022-0711 is a denial-of-service vulnerability in HAProxy where specially crafted HTTP responses containing Set-Cookie2 headers can trigger an inf...
Mar 2, 2022CVE-2022-23833 is a denial-of-service vulnerability in Django's MultiPartParser that allows attackers to cause infinite loops by submitting specially ...
Feb 3, 2022CVE-2022-23596 is a denial-of-service vulnerability in the Junrar Java RAR archive library where a malicious RAR file can trigger an infinite loop dur...
Feb 1, 2022This vulnerability allows remote attackers to cause permanent denial of service on Xerox VersaLink devices by sending a crafted TIFF file via unauthen...
Jan 26, 2022CVE-2021-23567 is a denial-of-service vulnerability in the colors.js npm package where versions after 1.4.0 contain an infinite loop in the americanFl...
Jan 14, 2022A vulnerability in Wireshark's RFC 7468 dissector allows attackers to cause a denial of service crash via specially crafted network packets or capture...
Dec 30, 2021This vulnerability in Wireshark's BitTorrent DHT dissector allows attackers to cause a denial of service (DoS) by triggering an infinite loop. Attacke...
Dec 30, 2021CVE-2021-42260 is an infinite loop vulnerability in TinyXML's parsing function that can be triggered by a specially crafted XML message. This leads to...
Oct 11, 2021This vulnerability in MediaWiki's Loops extension allows attackers to trigger infinite loops through parser functions, causing memory exhaustion and p...
Oct 6, 2021CVE-2021-37146 is an infinite loop vulnerability in the XMLRPC server of Open Robotics ros_comm package that allows remote attackers to cause Denial o...
Sep 28, 2021CVE-2021-1914 is an infinite loop vulnerability in Qualcomm Snapdragon chipsets where improper handling of unsupported input can cause a denial of ser...
Sep 8, 2021This vulnerability in Contiki 3.0's Telnet server causes connected clients to enter an infinite loop when the server silently quits before disconnecti...
Aug 10, 2021This vulnerability in Wireshark's DNP (Distributed Network Protocol) dissector allows attackers to cause a denial of service crash by injecting malici...
Jul 20, 2021This vulnerability in MediaWiki's CentralAuth extension allows attackers to cause denial of service through infinite loops when processing username re...
Jul 2, 2021This vulnerability in Pillow's FLI image decoder allows attackers to cause a denial-of-service (DoS) condition by triggering an infinite loop when pro...
Jun 2, 2021This vulnerability in F5 BIG-IP allows attackers to cause a denial of service by sending malformed HTTP/2 requests that trigger an infinite loop in th...
May 10, 2021Unbound DNS resolver versions before 1.9.5 contain a vulnerability where specially crafted DNS responses with compressed domain names can trigger an i...
Apr 27, 2021This vulnerability in Siemens Capital Embedded AR Classic, Nucleus NET, and related products allows attackers to cause denial of service by sending sp...
Apr 22, 2021This vulnerability in Pygments' SMLLexer causes an infinite loop when processing Standard ML source files containing only the 'exception' keyword, lea...
Mar 23, 2021This vulnerability in Go's XML encoding package causes an infinite loop when a custom TokenReader returns EOF in the middle of an XML element. This ca...
Mar 11, 2021This vulnerability in TensorFlow allows attackers to craft malicious TFLite models that cause infinite loops or stack overflows during evaluation. It ...
May 14, 2021This vulnerability allows authenticated users in GitLab to create malformed Wiki documents that bypass cycle detection, potentially causing a denial o...
Jan 22, 2026CVE-2025-7054 is a denial-of-service vulnerability in Cloudflare's quiche QUIC implementation where an unauthenticated attacker can trigger an infinit...
Aug 7, 2025This vulnerability allows network-adjacent attackers to cause a denial-of-service condition on Silicon Labs Gecko OS devices by sending specially craf...
Mar 26, 2025This vulnerability in Windows Standards-Based Storage Management Service allows attackers to cause a denial of service by sending specially crafted re...
Oct 8, 2024This vulnerability in Wireshark's MONGO and ZigBee TLV dissectors allows attackers to cause infinite loops via specially crafted network packets or ca...
May 14, 2024CVE-2024-42358 is a denial-of-service vulnerability in PDFio's TTF parser where maliciously crafted TrueType font files cause infinite loops and memor...
Aug 6, 2024This vulnerability allows a non-privileged user to trigger an infinite loop in Arm GPU kernel drivers through GPU memory operations, potentially via W...
Feb 3, 2025A vulnerability in Cisco's Snort 3 VBA feature allows unauthenticated remote attackers to crash the Snort 3 Detection Engine by sending specially craf...
Mar 4, 2026ImageMagick versions before 7.1.2-13 have a stack overflow vulnerability in the MSL (Magick Scripting Language) <write> command when writing to MSL fo...
Jan 20, 2026A vulnerability in Wireshark's MEGACO dissector causes an infinite loop when processing specially crafted packets, leading to denial of service. This ...
Dec 3, 2025This vulnerability in Wireshark's MONGO dissector causes an infinite loop when processing specially crafted network packets, leading to denial of serv...
Oct 10, 2025This CVE describes a kernel-level infinite loop vulnerability in the Linux UBI (Unsorted Block Images) subsystem. When wear-leveling operations fail d...
Oct 1, 2025A race condition in the Linux kernel's netlink subsystem can cause infinite retry loops when sending unicast messages, leading to CPU stalls and poten...
Sep 4, 2025A Linux kernel exFAT filesystem driver vulnerability allows infinite loops when processing corrupted directory cluster chains. This affects systems us...
Sep 4, 2025About Infinite Loop (CWE-835)
The product contains an iteration or loop with an exit condition that cannot be reached, leading to an infinite loop.
Our database tracks 137 CVEs classified as CWE-835, with 1 rated critical and 85 rated high severity. The average CVSS score for Infinite Loop vulnerabilities is 6.9.
External reference: View CWE-835 on MITRE CWE →
Monitor Infinite Loop Vulnerabilities
Get alerted when new Infinite Loop CVEs affect your infrastructure.
Start Monitoring Free