The product performs an iteration or loop without sufficiently limiting the number of times that the loop is executed.
Volume of CVEs assigned to CWE-834 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
108 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-45680HIGH OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, OBI replays BPF probe hits into histogram observations | Jun 2, 2026 | 7.5 | 30 | NO | NO |
CVE-2021-35515HIGH When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of | Jul 13, 2021 | 7.5 | 30 | NO | NO |
CVE-2026-50171MEDIUM Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.15, 20.3.22, and 19.2 | Jun 22, 2026 | 6.1 | 28 | NO | NO |
CVE-2021-39924HIGH Large loop in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file | Nov 19, 2021 | 7.5 | 28 | NO | NO |
CVE-2026-34043HIGH Serialize JavaScript to a superset of JSON that includes regular expressions and functions. Prior to version 7.0.5, there is a Denial of Service (DoS) vulnerability caused by CPU e | Mar 31, 2026 | 7.5 | 27 | NO | NO |
CVE-2025-67726HIGH Tornado is a Python web framework and asynchronous networking library. Versions 6.5.2 and below use an inefficient algorithm when parsing parameters for HTTP header values, potenti | Dec 12, 2025 | 7.5 | 27 | NO | NO |
CVE-2025-56571HIGH Finance.js v4.1.0 contains a Denial of Service (DoS) vulnerability via the IRR function’s depth parameter. Improper handling of the recursion/iteration limit can lead to excessive | Sep 30, 2025 | 7.5 | 27 | NO | NO |
CVE-2021-4190HIGH Large loop in the Kafka dissector in Wireshark 3.6.0 allows denial of service via packet injection or crafted capture file | Dec 30, 2021 | 7.5 | 27 | NO | NO |
CVE-2021-39923HIGH Large loop in the PNRP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file | Nov 19, 2021 | 7.5 | 26 | NO | NO |
CVE-2018-11813HIGH libjpeg 9c has a large loop because read_pixel in rdtarga.c mishandles EOF. | Jun 6, 2018 | 7.5 | 26 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.