CWE-835: Infinite Loop

The product contains an iteration or loop with an exit condition that cannot be reached, leading to an infinite loop.

137
Total CVEs
1
Critical
85
High
6.9
Avg CVSS

Yearly Trend

2026
17
2025
44
2024
33
2023
16
2022
11

Top Affected Vendors

1 Linux 27
2 Debian 15
3 Fedoraproject 10
4 Wireshark 7
5 Google 4
6 Redhat 4
7 Qualcomm 3
8 Gitlab 3
9 Cisco 3
10 Mediawiki 3

All Infinite Loop CVEs (137)

CVE-2023-45363
7.5

This vulnerability in MediaWiki's ApiPageSet.php allows attackers to trigger an infinite loop when querying pages with specific redirect and title con...

Oct 9, 2023
CVE-2023-42524
7.5

This vulnerability allows an attacker to cause a denial of service by triggering an infinite loop in the scanning engine of affected WithSecure securi...

Sep 18, 2023
CVE-2023-1108
7.5

CVE-2023-1108 is a denial-of-service vulnerability in Undertow's SSL/TLS implementation where an infinite loop in the handshake process can crash the ...

Sep 14, 2023
CVE-2023-20197
7.5

This vulnerability in ClamAV's HFS+ filesystem parser allows remote attackers to cause denial of service by submitting crafted HFS+ images. The scanni...

Aug 16, 2023
CVE-2020-35139
7.5

CVE-2020-35139 is a denial-of-service vulnerability in Faucet SDN Ryu's parser.py where specially crafted OFPBundleCtrlMsg messages can trigger an inf...

Aug 11, 2023
CVE-2023-34966
7.5

This CVE describes an infinite loop vulnerability in Samba's mdssvc RPC service for Spotlight. Attackers can send specially crafted RPC packets with a...

Jul 20, 2023
CVE-2023-38197
7.5

This vulnerability in Qt's XML parsing allows attackers to cause denial of service through infinite loops during recursive entity expansion. It affect...

Jul 13, 2023
CVE-2022-37013
7.5

CVE-2022-37013 is a denial-of-service vulnerability in Unified Automation OPC UA C++ Demo Server where remote attackers can send a specially crafted c...

Mar 29, 2023
CVE-2023-25824
7.5

This vulnerability in mod_gnutls (TLS module for Apache HTTPD) causes an endless loop when TLS connections timeout during blocking read operations, co...

Feb 23, 2023
CVE-2022-25851
7.5

CVE-2022-25851 is a denial-of-service vulnerability in jpeg-js library where specially crafted JPEG images cause infinite processing loops, consuming ...

Jun 10, 2022
CVE-2022-29190
7.5

CVE-2022-29190 is a denial-of-service vulnerability in Pion DTLS, a Go implementation of Datagram Transport Layer Security. Attackers can send special...

May 21, 2022
CVE-2022-21159
7.5

CVE-2022-21159 is a denial-of-service vulnerability in libiec61850's parseNormalModeParameters function where specially crafted IEC 61850 network mess...

Apr 15, 2022
CVE-2022-24763
7.5

CVE-2022-24763 is a denial-of-service vulnerability in PJSIP's XML parsing functionality that can cause applications to crash or become unresponsive. ...

Mar 30, 2022
CVE-2022-23352
7.5

This vulnerability in BigAnt Server v5.6.06 allows attackers to cause a Denial of Service (DoS) by exploiting an infinite loop condition (CWE-835). Th...

Mar 21, 2022
CVE-2022-0778
7.5

CVE-2022-0778 is a denial-of-service vulnerability in OpenSSL's BN_mod_sqrt() function that can cause infinite loops when parsing specially crafted ce...

Mar 15, 2022
CVE-2022-0711
7.5

CVE-2022-0711 is a denial-of-service vulnerability in HAProxy where specially crafted HTTP responses containing Set-Cookie2 headers can trigger an inf...

Mar 2, 2022
CVE-2022-23833
7.5

CVE-2022-23833 is a denial-of-service vulnerability in Django's MultiPartParser that allows attackers to cause infinite loops by submitting specially ...

Feb 3, 2022
CVE-2022-23596
7.5

CVE-2022-23596 is a denial-of-service vulnerability in the Junrar Java RAR archive library where a malicious RAR file can trigger an infinite loop dur...

Feb 1, 2022
CVE-2022-23968
7.5

This vulnerability allows remote attackers to cause permanent denial of service on Xerox VersaLink devices by sending a crafted TIFF file via unauthen...

Jan 26, 2022
CVE-2021-23567
7.5

CVE-2021-23567 is a denial-of-service vulnerability in the colors.js npm package where versions after 1.4.0 contain an infinite loop in the americanFl...

Jan 14, 2022
CVE-2021-4182
7.5

A vulnerability in Wireshark's RFC 7468 dissector allows attackers to cause a denial of service crash via specially crafted network packets or capture...

Dec 30, 2021
CVE-2021-4184
7.5

This vulnerability in Wireshark's BitTorrent DHT dissector allows attackers to cause a denial of service (DoS) by triggering an infinite loop. Attacke...

Dec 30, 2021
CVE-2021-42260
7.5

CVE-2021-42260 is an infinite loop vulnerability in TinyXML's parsing function that can be triggered by a specially crafted XML message. This leads to...

Oct 11, 2021
CVE-2021-42040
7.5

This vulnerability in MediaWiki's Loops extension allows attackers to trigger infinite loops through parser functions, causing memory exhaustion and p...

Oct 6, 2021
CVE-2021-37146
7.5

CVE-2021-37146 is an infinite loop vulnerability in the XMLRPC server of Open Robotics ros_comm package that allows remote attackers to cause Denial o...

Sep 28, 2021
CVE-2021-1914
7.5

CVE-2021-1914 is an infinite loop vulnerability in Qualcomm Snapdragon chipsets where improper handling of unsupported input can cause a denial of ser...

Sep 8, 2021
CVE-2021-38387
7.5

This vulnerability in Contiki 3.0's Telnet server causes connected clients to enter an infinite loop when the server silently quits before disconnecti...

Aug 10, 2021
CVE-2021-22235
7.5

This vulnerability in Wireshark's DNP (Distributed Network Protocol) dissector allows attackers to cause a denial of service crash by injecting malici...

Jul 20, 2021
CVE-2021-36125
7.5

This vulnerability in MediaWiki's CentralAuth extension allows attackers to cause denial of service through infinite loops when processing username re...

Jul 2, 2021
CVE-2021-28676
7.5

This vulnerability in Pillow's FLI image decoder allows attackers to cause a denial-of-service (DoS) condition by triggering an infinite loop when pro...

Jun 2, 2021
CVE-2021-23009
7.5

This vulnerability in F5 BIG-IP allows attackers to cause a denial of service by sending malformed HTTP/2 requests that trigger an infinite loop in th...

May 10, 2021
CVE-2019-25040
7.5

Unbound DNS resolver versions before 1.9.5 contain a vulnerability where specially crafted DNS responses with compressed domain names can trigger an i...

Apr 27, 2021
CVE-2021-25663
7.5

This vulnerability in Siemens Capital Embedded AR Classic, Nucleus NET, and related products allows attackers to cause denial of service by sending sp...

Apr 22, 2021
CVE-2021-20270
7.5

This vulnerability in Pygments' SMLLexer causes an infinite loop when processing Standard ML source files containing only the 'exception' keyword, lea...

Mar 23, 2021
CVE-2021-27918
7.5

This vulnerability in Go's XML encoding package causes an infinite loop when a custom TokenReader returns EOF in the middle of an XML element. This ca...

Mar 11, 2021
CVE-2021-29591
7.3

This vulnerability in TensorFlow allows attackers to craft malicious TFLite models that cause infinite loops or stack overflows during evaluation. It ...

May 14, 2021
CVE-2025-13335
6.5

This vulnerability allows authenticated users in GitLab to create malformed Wiki documents that bypass cycle detection, potentially causing a denial o...

Jan 22, 2026
CVE-2025-7054
6.5

CVE-2025-7054 is a denial-of-service vulnerability in Cloudflare's quiche QUIC implementation where an unauthenticated attacker can trigger an infinit...

Aug 7, 2025
CVE-2025-2838
6.5

This vulnerability allows network-adjacent attackers to cause a denial-of-service condition on Silicon Labs Gecko OS devices by sending specially craf...

Mar 26, 2025
CVE-2024-43512
6.5

This vulnerability in Windows Standards-Based Storage Management Service allows attackers to cause a denial of service by sending specially crafted re...

Oct 8, 2024
CVE-2024-4854
6.4

This vulnerability in Wireshark's MONGO and ZigBee TLV dissectors allows attackers to cause infinite loops via specially crafted network packets or ca...

May 14, 2024
CVE-2024-42358
6.2

CVE-2024-42358 is a denial-of-service vulnerability in PDFio's TTF parser where maliciously crafted TrueType font files cause infinite loops and memor...

Aug 6, 2024
CVE-2024-6790
6.1

This vulnerability allows a non-privileged user to trigger an infinite loop in Arm GPU kernel drivers through GPU memory operations, potentially via W...

Feb 3, 2025
CVE-2026-20054
5.8

A vulnerability in Cisco's Snort 3 VBA feature allows unauthenticated remote attackers to crash the Snort 3 Detection Engine by sending specially craf...

Mar 4, 2026
CVE-2026-23874
5.5

ImageMagick versions before 7.1.2-13 have a stack overflow vulnerability in the MSL (Magick Scripting Language) <write> command when writing to MSL fo...

Jan 20, 2026
CVE-2025-13946
5.5

A vulnerability in Wireshark's MEGACO dissector causes an infinite loop when processing specially crafted packets, leading to denial of service. This ...

Dec 3, 2025
CVE-2025-11626
5.5

This vulnerability in Wireshark's MONGO dissector causes an infinite loop when processing specially crafted network packets, leading to denial of serv...

Oct 10, 2025
CVE-2023-53481
5.5

This CVE describes a kernel-level infinite loop vulnerability in the Linux UBI (Unsorted Block Images) subsystem. When wear-leveling operations fail d...

Oct 1, 2025
CVE-2025-38727
5.5

A race condition in the Linux kernel's netlink subsystem can cause infinite retry loops when sending unicast messages, leading to CPU stalls and poten...

Sep 4, 2025
CVE-2025-38692
5.5

A Linux kernel exFAT filesystem driver vulnerability allows infinite loops when processing corrupted directory cluster chains. This affects systems us...

Sep 4, 2025

About Infinite Loop (CWE-835)

The product contains an iteration or loop with an exit condition that cannot be reached, leading to an infinite loop.

Our database tracks 137 CVEs classified as CWE-835, with 1 rated critical and 85 rated high severity. The average CVSS score for Infinite Loop vulnerabilities is 6.9.

External reference: View CWE-835 on MITRE CWE →

Monitor Infinite Loop Vulnerabilities

Get alerted when new Infinite Loop CVEs affect your infrastructure.

Start Monitoring Free