CWE-674 · 521 записей
Uncontrolled Recursion
CVE этого класса
524 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
50В плане | CVE-2024-25111Эксплойта нет | SQUID-2024:1 Denial of Service in HTTP Chunked Decodingsquid-cache · squid · CWE-674 | Высокая7,5 | — | 65,3 % | 6 мар. 2024 г. |
47В плане | CVE-2023-50269Эксплойта нет | SQUID-2023:10 Denial of Service in HTTP Request parsingsquid-cache · squid · CWE-674 | Высокая7,5 | — | 57,6 % | 14 дек. 2023 г. |
41В плане | CVE-2021-42697Proof of concept | Akka HTTP 10.1.x before 10.1.15 and 10.2.x before 10.2.7 can encounter stack exhaustion while parsing HTTP headers, which allows a remote atakka · http server · CWE-674 | Высокая7,5 | — | 36,1 % | 2 нояб. 2021 г. |
39Наблюдать | CVE-2018-1000618Эксплойта нет | EOSIO/eos eos version after commit f1545dd0ae2b77580c2236fdb70ae7138d2c7168 contains a stack overflow vulnerability in abi_serializer that ceosio project · eos · CWE-674 | Критическая9,8 | — | 1,5 % | 9 июл. 2018 г. |
39Наблюдать | CVE-2021-41752Эксплойта нет | Stack overflow vulnerability in Jerryscript before commit e1ce7dd7271288be8c0c8136eea9107df73a8ce2 on Oct 20, 2021 due to an unbounded recurjerryscript · jerryscript · CWE-674 | Критическая9,8 | — | 1,2 % | 5 апр. 2022 г. |
39Наблюдать | CVE-2023-51803Эксплойта нет | LinuxServer.io Heimdall before 2.5.7 does not prevent use of icons that have non-image data such as the "<?php ?>" substring.CWE-674 | Критическая9,8 | — | 0,7 % | 31 мар. 2024 г. |
39Наблюдать | CVE-2026-43185Эксплойта нет | ksmbd: fix signededness bug in smb_direct_prepare_negotiation()linux · linux kernel · CWE-674 | Критическая9,8 | — | 0,7 % | 6 мая 2026 г. |
39Наблюдать | CVE-2026-25971Эксплойта нет | ImageMagick's MSL: Stack overflow in ProcessMSLScriptimagemagick · imagemagick · CWE-674 | Критическая9,8 | — | 0,4 % | 23 февр. 2026 г. |
37Наблюдать | CVE-2025-10728Эксплойта нет | Uncontrolled recursion in Qt SVG moduleqt · qt · CWE-674 | Критическая9,4 | — | 0,2 % | 3 окт. 2025 г. |
36Наблюдать | CVE-2019-9543Эксплойта нет | An issue was discovered in Poppler 0.74.0.freedesktop · poppler · CWE-674 | Высокая8,8 | — | 3,3 % | 1 мар. 2019 г. |
36Наблюдать | CVE-2019-9144Эксплойта нет | An issue was discovered in Exiv2 0.27.exiv2 · exiv2 · CWE-674 | Высокая8,8 | — | 2,8 % | 25 февр. 2019 г. |
36Наблюдать | CVE-2019-9143Эксплойта нет | An issue was discovered in Exiv2 0.27.exiv2 · exiv2 · CWE-674 | Высокая8,8 | — | 2,8 % | 25 февр. 2019 г. |
36Наблюдать | CVE-2019-9545Эксплойта нет | An issue was discovered in Poppler 0.74.0.freedesktop · poppler · CWE-674 | Высокая8,8 | — | 1,8 % | 1 мар. 2019 г. |
36Наблюдать | CVE-2026-40324Эксплойта нет | Hot Chocolate's Utf8GraphQLParser has Stack Overflow via Deeply Nested GraphQL Documentschillicream · graphql-platform · CWE-674 | Критическая9,1 | — | 1,0 % | 17 апр. 2026 г. |
36Наблюдать | CVE-2026-32327Эксплойта нет | Apache Portable Runtime Utility: apr-util XML stack recursion crashapache · apr-util · CWE-674 | Критическая9,1 | — | 0,5 % | 6 авг. 2026 г. |
35Наблюдать | CVE-2007-1285Proof of concept | The Zend Engine in PHP 4.x before 4.4.7, and 5.x before 5.2.2, allows remote attackers to cause a denial of service (stack exhaustion and PHphp · php · CWE-674 | Высокая7,5 | — | 18,2 % | 6 мар. 2007 г. |
35Наблюдать | CVE-2024-37973Эксплойта нет | Secure Boot Security Feature Bypass Vulnerabilitymicrosoft · windows 10 1507 · CWE-674 | Высокая8,8 | — | 0,6 % | 9 июл. 2024 г. |
34Наблюдать | CVE-2026-61551Эксплойта нет | Icinga 2: Stack overflow via deeply nested JSON objectsicinga · icinga2 · CWE-674 | Высокая8,6 | — | 0,9 % | 18 сент. 2026 г. |
34Наблюдать | CVE-2026-3520Эксплойта нет | Multer vulnerable to Denial of Service via uncontrolled recursionexpressjs · multer · CWE-674 | Высокая8,7 | — | 0,9 % | 4 мар. 2026 г. |
34Наблюдать | CVE-2026-93450Эксплойта нет | go-openapi/swag jsonutils before 0.27.1 Uncontrolled Recursion in Ordered JSON Marshal and Unmarshalgo-openapi · swag · CWE-674 | Высокая8,7 | — | 0,9 % | 17 сент. 2026 г. |
34Наблюдать | CVE-2026-41673Эксплойта нет | xmldom: Denial of service via uncontrolled recursion in XML serializationxmldom · xmldom · CWE-674 | Высокая8,7 | — | 0,9 % | 7 мая 2026 г. |
34Наблюдать | CVE-2026-93687Эксплойта нет | braces through 3.0.3 Stack Overflow via Deeply Nested Patternsmicromatch · braces · CWE-674 | Высокая8,7 | — | 0,7 % | 18 сент. 2026 г. |
34Наблюдать | CVE-2026-41636Эксплойта нет | Apache Thrift: Node.js skip() recursionapache · thrift · CWE-674 | Высокая8,7 | — | 0,7 % | 28 апр. 2026 г. |
34Наблюдать | CVE-2026-69220Эксплойта нет | RabbitMQ Java client ValueReader: Unbounded recursive table/array nesting causes StackOverflowError DoSrabbitmq · rabbitmq-java-client · CWE-674 | Высокая8,7 | — | 0,7 % | 18 авг. 2026 г. |
34Наблюдать | CVE-2026-25048Эксплойта нет | xgrammar: Multi-layer nesting causes DoSmlc-ai · xgrammar · CWE-674 | Высокая8,7 | — | 0,7 % | 5 мар. 2026 г. |
- CVE-2024-2511150В плане
SQUID-2024:1 Denial of Service in HTTP Chunked Decoding
ВысокаяCVSS 7,5Эксплойта нетEPSS 65 %squid-cache · squid6 мар. 2024 г.
- CVE-2023-5026947В плане
SQUID-2023:10 Denial of Service in HTTP Request parsing
ВысокаяCVSS 7,5Эксплойта нетEPSS 58 %squid-cache · squid14 дек. 2023 г.
- CVE-2021-4269741В плане
Akka HTTP 10.1.x before 10.1.15 and 10.2.x before 10.2.7 can encounter stack exhaustion while parsing HTTP headers, which allows a remote at
ВысокаяCVSS 7,5Proof of conceptEPSS 36 %akka · http server2 нояб. 2021 г.
- CVE-2018-100061839Наблюдать
EOSIO/eos eos version after commit f1545dd0ae2b77580c2236fdb70ae7138d2c7168 contains a stack overflow vulnerability in abi_serializer that c
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %eosio project · eos9 июл. 2018 г.
- CVE-2021-4175239Наблюдать
Stack overflow vulnerability in Jerryscript before commit e1ce7dd7271288be8c0c8136eea9107df73a8ce2 on Oct 20, 2021 due to an unbounded recur
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %jerryscript · jerryscript5 апр. 2022 г.
- CVE-2023-5180339Наблюдать
LinuxServer.io Heimdall before 2.5.7 does not prevent use of icons that have non-image data such as the "<?php ?>" substring.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %31 мар. 2024 г.
- CVE-2026-4318539Наблюдать
ksmbd: fix signededness bug in smb_direct_prepare_negotiation()
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %linux · linux kernel6 мая 2026 г.
- CVE-2026-2597139Наблюдать
ImageMagick's MSL: Stack overflow in ProcessMSLScript
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %imagemagick · imagemagick23 февр. 2026 г.
- CVE-2025-1072837Наблюдать
Uncontrolled recursion in Qt SVG module
КритическаяCVSS 9,4Эксплойта нетEPSS 0 %qt · qt3 окт. 2025 г.
- CVE-2019-954336Наблюдать
An issue was discovered in Poppler 0.74.0.
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %freedesktop · poppler1 мар. 2019 г.
- CVE-2019-914436Наблюдать
An issue was discovered in Exiv2 0.27.
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %exiv2 · exiv225 февр. 2019 г.
- CVE-2019-914336Наблюдать
An issue was discovered in Exiv2 0.27.
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %exiv2 · exiv225 февр. 2019 г.
- CVE-2019-954536Наблюдать
An issue was discovered in Poppler 0.74.0.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %freedesktop · poppler1 мар. 2019 г.
- CVE-2026-4032436Наблюдать
Hot Chocolate's Utf8GraphQLParser has Stack Overflow via Deeply Nested GraphQL Documents
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %chillicream · graphql-platform17 апр. 2026 г.
- CVE-2026-3232736Наблюдать
Apache Portable Runtime Utility: apr-util XML stack recursion crash
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %apache · apr-util6 авг. 2026 г.
- CVE-2007-128535Наблюдать
The Zend Engine in PHP 4.x before 4.4.7, and 5.x before 5.2.2, allows remote attackers to cause a denial of service (stack exhaustion and PH
ВысокаяCVSS 7,5Proof of conceptEPSS 18 %php · php6 мар. 2007 г.
- CVE-2024-3797335Наблюдать
Secure Boot Security Feature Bypass Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %microsoft · windows 10 15079 июл. 2024 г.
- CVE-2026-6155134Наблюдать
Icinga 2: Stack overflow via deeply nested JSON objects
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %icinga · icinga218 сент. 2026 г.
- CVE-2026-352034Наблюдать
Multer vulnerable to Denial of Service via uncontrolled recursion
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %expressjs · multer4 мар. 2026 г.
- CVE-2026-9345034Наблюдать
go-openapi/swag jsonutils before 0.27.1 Uncontrolled Recursion in Ordered JSON Marshal and Unmarshal
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %go-openapi · swag17 сент. 2026 г.
- CVE-2026-4167334Наблюдать
xmldom: Denial of service via uncontrolled recursion in XML serialization
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %xmldom · xmldom7 мая 2026 г.
- CVE-2026-9368734Наблюдать
braces through 3.0.3 Stack Overflow via Deeply Nested Patterns
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %micromatch · braces18 сент. 2026 г.
- CVE-2026-4163634Наблюдать
Apache Thrift: Node.js skip() recursion
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %apache · thrift28 апр. 2026 г.
- CVE-2026-6922034Наблюдать
RabbitMQ Java client ValueReader: Unbounded recursive table/array nesting causes StackOverflowError DoS
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %rabbitmq · rabbitmq-java-client18 авг. 2026 г.
- CVE-2026-2504834Наблюдать
xgrammar: Multi-layer nesting causes DoS
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %mlc-ai · xgrammar5 мар. 2026 г.