The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.
Volume of CVEs assigned to CWE-674 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
464 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-45105MEDIUM Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker wit | Dec 18, 2021 | 5.9 | 76 | NO | NO |
CVE-2021-42697HIGH Akka HTTP 10.1.x before 10.1.15 and 10.2.x before 10.2.7 can encounter stack exhaustion while parsing HTTP headers, which allows a remote attacker to conduct a Denial of Service at | Nov 2, 2021 | 7.5 | 56 | NO | YES |
CVE-2024-25111HIGH Squid is a web proxy cache. Starting in version 3.5.27 and prior to version 6.8, Squid may be vulnerable to a Denial of Service attack against HTTP Chunked decoder due to an uncont | Mar 6, 2024 | 7.5 | 55 | NO | NO |
CVE-2023-50269HIGH Squid is a caching proxy for the Web. Due to an Uncontrolled Recursion bug in versions 2.6 through 2.7.STABLE9, versions 3.1 through 5.9, and versions 6.0.1 through 6.5, Squid may | Dec 14, 2023 | 7.5 | 50 | NO | NO |
CVE-2017-8536MEDIUM The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows S | May 26, 2017 | 5.5 | 38 | NO | YES |
CVE-2017-8537MEDIUM The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows S | May 26, 2017 | 5.5 | 37 | NO | YES |
CVE-2017-8535MEDIUM The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows S | May 26, 2017 | 5.5 | 37 | NO | YES |
CVE-2007-1285HIGH The Zend Engine in PHP 4.x before 4.4.7, and 5.x before 5.2.2, allows remote attackers to cause a denial of service (stack exhaustion and PHP crash) via deeply nested arrays, which | Mar 6, 2007 | 7.5 | 37 | NO | YES |
CVE-2026-8936HIGH Fixed a VM panic caused by unbounded recursion in the grpcfuse kernel module when a container created deeply nested directories on a bind-mounted host folder and triggered a dentry | Jun 2, 2026 | 8.2 | 36 | NO | NO |
CVE-2026-43185CRITICAL In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix signededness bug in smb_direct_prepare_negotiation()
smb_direct_prepare_negotiation() casts an unsi | May 6, 2026 | 9.8 | 36 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.